CVE-2025-0160: IBM FlashSystem code execution
IBM FlashSystem (IBM Storage Virtualize (8.5.0.0 through 8.5.0.13, 8.5.1.0, 8.5.2.0 through 8.5.2.3, 8.5.3.0 through 8.5.3.1, 8.5.4.0, 8.6.0.0 through 8.6.0.5, 8.6.1.0, 8.6.2.0 through 8.6.2.1, 8.6.3.0, 8.7.0.0 through 8.7.0.2, 8.7.1.0, 8.7.2.0 through 8.7.2.1) could allow a remote attacker with access to the system to execute arbitrary Java code due to improper restrictions in the RPCAdapter service.
Other sources
IBM FlashSystems could allow a remote attacker with access to the system to execute arbitrary Java code due to improper restrictions in the RPCAdapter service.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0160?
CVE-2025-0160 has been assigned a medium severity level due to its potential for remote exploits.
How do I fix CVE-2025-0160?
To mitigate CVE-2025-0160, update your IBM Spectrum Virtualize software to the latest available versions as recommended by IBM.
What versions of IBM Spectrum Virtualize are affected by CVE-2025-0160?
CVE-2025-0160 affects versions of IBM Spectrum Virtualize from 8.5.0.0 to 8.7.2.1.
What type of vulnerability is CVE-2025-0160?
CVE-2025-0160 is a remote code execution vulnerability that could allow unauthorized access.
Is there a workaround for CVE-2025-0160 while I prepare to update?
While an official workaround is not specified, restricting access to affected systems and implementing strong firewall rules can help mitigate risks.