CVE-2025-0160
IBM FlashSystem (IBM Storage Virtualize (8.5.0.0 through 8.5.0.13, 8.5.1.0, 8.5.2.0 through 8.5.2.3, 8.5.3.0 through 8.5.3.1, 8.5.4.0, 8.6.0.0 through 8.6.0.5, 8.6.1.0, 8.6.2.0 through 8.6.2.1, 8.6.3.0, 8.7.0.0 through 8.7.0.2, 8.7.1.0, 8.7.2.0 through 8.7.2.1) could allow a remote attacker with access to the system to execute arbitrary Java code due to improper restrictions in the RPCAdapter service.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.1
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.51%
- CWE
- CWE-114
- Published
- 2025-02-28
- Last modified
- 2026-03-13
Affected products
- IBM Storage Virtualize
- IBM Storage Virtualize
- IBM Storage Virtualize
- IBM Storage Virtualize
- IBM Storage Virtualize
- IBM Storage Virtualize
- IBM Storage Virtualize
- IBM Storage Virtualize
Weakness type
Related vulnerabilities
- CVE-2026-26945 — Dell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.181, 15G and 16G...
- CVE-2026-29046 — TinyWeb: HTTP Header Control Character Injection into CGI Environment
- CVE-2025-36250 — AIX Code Execution
- CVE-2025-36251 — AIX Command Execution
- CVE-2025-46370 — Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contain a Process Control...
- CVE-2025-1950 — IBM Hardware Management Console - Power Systems command execution
- CVE-2024-56347 — IBM AIX command execution
- CVE-2024-56346 — IBM AIX command execution