CRITICAL🇵🇱 Wersja polska

CVE-2025-0159

CVSS 9.1v3.1pub. 2025-02-28upd. 2025-08-18

IBM FlashSystem (IBM Storage Virtualize (8.5.0.0 through 8.5.0.13, 8.5.1.0, 8.5.2.0 through 8.5.2.3, 8.5.3.0 through 8.5.3.1, 8.5.4.0, 8.6.0.0 through 8.6.0.5, 8.6.1.0, 8.6.2.0 through 8.6.2.1, 8.6.3.0, 8.7.0.0 through 8.7.0.2, 8.7.1.0, 8.7.2.0 through 8.7.2.1) could allow a remote attacker to bypass RPCAdapter endpoint authentication by sending a specifically crafted HTTP request.

🤖 AI Analysis
How it works

An attacker sends a specially crafted HTTP request to the RPCAdapter endpoint, which allows them to bypass required identity verification (CWE-288, CWE-306). The authentication mechanism is not properly enforced for this interface, causing the request to be processed without prior authorization. The attack requires no privileges or user interaction and can be conducted remotely over the network.

Impact

An attacker can gain unauthorized access to functions exposed by RPCAdapter, leading to a breach of confidentiality and integrity of data stored or managed by the IBM FlashSystem host system.

Mitigation & patch

Apply patches available from the vendor according to the references: https://www.ibm.com/support/pages/node/7184182

Who is affected

IBM FlashSystem (IBM Storage Virtualize) in versions: 8.5.0.0–8.5.0.13, 8.5.1.0, 8.5.2.0–8.5.2.3, 8.5.3.0–8.5.3.1, 8.5.4.0, 8.6.0.0–8.6.0.5, 8.6.1.0, 8.6.2.0–8.6.2.1, 8.6.3.0, 8.7.0.0–8.7.0.2, 8.7.1.0, 8.7.2.0–8.7.2.1

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • IBM Storage Virtualize

    APP
    Ibm
    8.5.1.08.5.3.08.5.3.18.5.4.08.6.1.08.6.2.08.6.2.18.6.3.08.7.1.08.7.2.08.7.2.18.7.0.0 – 8.7.0.3 (excl.)8.6.0.0 – 8.6.0.6 (excl.)8.5.2.0 – 8.5.2.38.5 – 8.5.0.14 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-36118HIGH7.5same product

IBM Storage Virtualize 8.4, 8.5, 8.7, and 9.1 IKEv1 implementation allows remote attackers to obtain sensitive...

CVE-2025-36120HIGH8.8same product

IBM Storage Virtualize 8.4, 8.5, 8.6, and 8.7 could allow an authenticated user to escalate their privileges i...

CVE-2025-0160HIGH8.1same product

IBM FlashSystem (IBM Storage Virtualize (8.5.0.0 through 8.5.0.13, 8.5.1.0, 8.5.2.0 through 8.5.2.3, 8.5.3.0 t...

CVE-2023-43042HIGH7.5same product

IBM SAN Volume Controller, IBM Storwize, IBM FlashSystem and IBM Storage Virtualize 8.3 products use default p...

CVE-2025-1351MEDIUM6.7same product

IBM Storage Virtualize 8.5, 8.6, and 8.7 products could allow a user to escalate their privileges to that of a...