# CVE-2025-0160

## Summary

- **CVE ID:** CVE-2025-0160
- **Severity:** HIGH
- **CVSS Score:** 8.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-114
- **Published:** Feb 28, 2025
- **Last Modified:** Mar 13, 2026

## Description

IBM FlashSystem (IBM Storage Virtualize (8.5.0.0 through 8.5.0.13, 8.5.1.0, 8.5.2.0 through 8.5.2.3, 8.5.3.0 through 8.5.3.1, 8.5.4.0, 8.6.0.0 through 8.6.0.5, 8.6.1.0, 8.6.2.0 through 8.6.2.1, 8.6.3.0, 8.7.0.0 through 8.7.0.2, 8.7.1.0, 8.7.2.0 through 8.7.2.1)  could allow a remote attacker with access to the system to execute arbitrary Java code due to improper restrictions in the RPCAdapter service.

## Affected Products

- IBM — Storage Virtualize (8.5.0.0)
- IBM — Storage Virtualize (8.5.1.0)
- IBM — Storage Virtualize (8.5.2.0)
- IBM — Storage Virtualize (8.5.3.0)
- IBM — Storage Virtualize (8.5.4.0)
- IBM — Storage Virtualize (8.6.0.0)
- IBM — Storage Virtualize (8.6.1.0)
- IBM — Storage Virtualize (8.6.2.0)
- IBM — Storage Virtualize (8.6.3.0)
- IBM — Storage Virtualize (8.7.1.0)
- IBM — Storage Virtualize (8.7.2.0)

## References

- [CNA](https://www.ibm.com/support/pages/node/7184182)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.51%
- **EPSS Percentile:** 42.1

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._