nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-62289 CVE-2025-62289
MEDIUM
Record summary
CVE-2025-62289 has a selected CVSS score of 4.9 (medium).
Description
Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Filesystems). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle ZFS Storage Appliance Kit. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
Description source: GitHub Advisory
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 21, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Oracle ZFS Storage Appliance KitBrowse Oracle Corporation / Oracle ZFS Storage Appliance Kit | CVE List | 8.8 | affected |
References
2Oracle AdvisoryVendor advisory
https://www.oracle.com/security-alerts/cpuoct2025.html