TeleMessage TM SGNL Initialization of a Resource with an Insecure Default Vulnerability
TeleMessage · TM SGNL
Date added (CISA)
2025-07-01
Remediation due
2025-07-22
Known ransomware use
Not indicated
Remediation priority
P2 — past CISA due date
Description
TeleMessage TM SGNL contains an initialization of a resource with an insecure default vulnerability. This vulnerability relies on how the Spring Boot Actuator is configured with an exposed heap dump endpoint at a /heapdump URI.