CVE-2025-0160
HIGHDescription
IBM FlashSystem (IBM Storage Virtualize (8.5.0.0 through 8.5.0.13, 8.5.1.0, 8.5.2.0 through 8.5.2.3, 8.5.3.0 through 8.5.3.1, 8.5.4.0, 8.6.0.0 through 8.6.0.5, 8.6.1.0, 8.6.2.0 through 8.6.2.1, 8.6.3.0, 8.7.0.0 through 8.7.0.2, 8.7.1.0, 8.7.2.0 through 8.7.2.1) could allow a remote attacker with access to the system to execute arbitrary Java code due to improper restrictions in the RPCAdapter service.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| ibm | storage_virtualize |
| ibm | storage_virtualize |
| ibm | storage_virtualize |
| ibm | storage_virtualize |
| ibm | storage_virtualize |
| ibm | storage_virtualize |
| ibm | storage_virtualize |
| ibm | storage_virtualize |
| ibm | storage_virtualize |
| ibm | storage_virtualize |
| ibm | storage_virtualize |
| ibm | storage_virtualize |
| ibm | storage_virtualize |
| ibm | storage_virtualize |
| ibm | storage_virtualize |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2025-0160? +
How severe is CVE-2025-0160? +
What products are affected by CVE-2025-0160? +
How do I check if I'm vulnerable to CVE-2025-0160? +
Related Vulnerabilities
IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) …
IBM AIX 7.2 and 7.3 nimesis NIM master service could allow a remote attacker to execute arbitrary commands due to …
IBM AIX 7.2 and 7.3 nimsh service SSL/TLS protection mechanisms could allow a remote attacker to execute arbitrary commands due …
IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 nimsh service SSL/TLS implementations could allow a remote attacker …
IBM Hardware Management Console - Power Systems V10.2.1030.0 and V10.3.1050.0 could allow a local user to execute commands locally due …
IBM AIX 7.3, VIOS 4.1's Perl implementation could allow a non-privileged local user to exploit a vulnerability to execute arbitrary …