9.8

CVE-2025-0160

IBM FlashSystem code execution

IBM FlashSystem (IBM Storage Virtualize (8.5.0.0 through 8.5.0.13, 8.5.1.0, 8.5.2.0 through 8.5.2.3, 8.5.3.0 through 8.5.3.1, 8.5.4.0, 8.6.0.0 through 8.6.0.5, 8.6.1.0, 8.6.2.0 through 8.6.2.1, 8.6.3.0, 8.7.0.0 through 8.7.0.2, 8.7.1.0, 8.7.2.0 through 8.7.2.1)  could allow a remote attacker with access to the system to execute arbitrary Java code due to improper restrictions in the RPCAdapter service.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IbmStorage Virtualize Version >= 8.5 < 8.5.0.14
IbmStorage Virtualize Version >= 8.5.2.0 <= 8.5.2.3
IbmStorage Virtualize Version >= 8.6.0.0 < 8.6.0.6
IbmStorage Virtualize Version >= 8.7.0.0 < 8.7.0.3
IbmStorage Virtualize Version8.5.1.0
IbmStorage Virtualize Version8.5.3.0
IbmStorage Virtualize Version8.5.3.1
IbmStorage Virtualize Version8.5.4.0
IbmStorage Virtualize Version8.6.1.0
IbmStorage Virtualize Version8.6.2.0
IbmStorage Virtualize Version8.6.2.1
IbmStorage Virtualize Version8.6.3.0
IbmStorage Virtualize Version8.7.1.0
IbmStorage Virtualize Version8.7.2.0
IbmStorage Virtualize Version8.7.2.1
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.413
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
psirt@us.ibm.com 8.1 2.2 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-114 Process Control

Executing commands or loading libraries from an untrusted source or in an untrusted environment can cause an application to execute malicious commands (and payloads) on behalf of an attacker.