CVE-2025-0160

HIGH

IBM FlashSystem - Remote Code Execution

Title source: manual
STIX 2.1

Description

IBM FlashSystem (IBM Storage Virtualize (8.5.0.0 through 8.5.0.13, 8.5.1.0, 8.5.2.0 through 8.5.2.3, 8.5.3.0 through 8.5.3.1, 8.5.4.0, 8.6.0.0 through 8.6.0.5, 8.6.1.0, 8.6.2.0 through 8.6.2.1, 8.6.3.0, 8.7.0.0 through 8.7.0.2, 8.7.1.0, 8.7.2.0 through 8.7.2.1) could allow a remote attacker with access to the system to execute arbitrary Java code due to improper restrictions in the RPCAdapter service.

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory
https://www.ibm.com/support/pages/node/7184182

Scores

CVSS v3 8.1
EPSS 0.0020
EPSS Percentile 41.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-114
Status published
Products (12)
ibm/storage_virtualize 8.5.1.0
ibm/storage_virtualize 8.5.3.0
ibm/storage_virtualize 8.5.3.1
ibm/storage_virtualize 8.5.4.0
ibm/storage_virtualize 8.6.1.0
ibm/storage_virtualize 8.6.2.0
ibm/storage_virtualize 8.6.2.1
ibm/storage_virtualize 8.6.3.0
ibm/storage_virtualize 8.7.1.0
ibm/storage_virtualize 8.7.2.0
... and 2 more
Published Feb 28, 2025
Tracked Since Feb 18, 2026