9.8

CVE-2025-0160

IBM FlashSystem code execution

IBM FlashSystem (IBM Storage Virtualize (8.5.0.0 through 8.5.0.13, 8.5.1.0, 8.5.2.0 through 8.5.2.3, 8.5.3.0 through 8.5.3.1, 8.5.4.0, 8.6.0.0 through 8.6.0.5, 8.6.1.0, 8.6.2.0 through 8.6.2.1, 8.6.3.0, 8.7.0.0 through 8.7.0.2, 8.7.1.0, 8.7.2.0 through 8.7.2.1)  could allow a remote attacker with access to the system to execute arbitrary Java code due to improper restrictions in the RPCAdapter service.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Storage Virtualize Version >= 8.5 < 8.5.0.14
Ibm ≫ Storage Virtualize Version >= 8.5.2.0 <= 8.5.2.3
Ibm ≫ Storage Virtualize Version >= 8.6.0.0 < 8.6.0.6
Ibm ≫ Storage Virtualize Version >= 8.7.0.0 < 8.7.0.3
Ibm ≫ Storage Virtualize Version 8.5.1.0
Ibm ≫ Storage Virtualize Version 8.5.3.0
Ibm ≫ Storage Virtualize Version 8.5.3.1
Ibm ≫ Storage Virtualize Version 8.5.4.0
Ibm ≫ Storage Virtualize Version 8.6.1.0
Ibm ≫ Storage Virtualize Version 8.6.2.0
Ibm ≫ Storage Virtualize Version 8.6.2.1
Ibm ≫ Storage Virtualize Version 8.6.3.0
Ibm ≫ Storage Virtualize Version 8.7.1.0
Ibm ≫ Storage Virtualize Version 8.7.2.0
Ibm ≫ Storage Virtualize Version 8.7.2.1
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.51% 0.402
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
IBM 8.1 2.2 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-114 Process Control

Executing commands or loading libraries from an untrusted source or in an untrusted environment can cause an application to execute malicious commands (and payloads) on behalf of an attacker.

https://www.ibm.com/support/pages/node/7184182
Vendor Advisory