CVE-2025-64650: IBM Storage Defender - Resiliency Service Information Disclosure
Published Dec 8, 2025
·Updated
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.18 could disclose sensitive user credentials in log files.
Other sources
IBM Storage Defender - Resiliency Service could disclose sensitive user credentials in log files.
— IBM
Affected Software
3 affected components
IBM Storage Defender - Resiliency Service>=2.0.0<=2.0.18
IBM Storage Defender - Resiliency Service<=2.0.0 - 2.0.18
IBM Storage Defender Resiliency Service>=2.0<=2.0.18
Remediation
Information
Remediation/Fixes The Connection Manager included with Defender 2.1.0 and newer provides the fixes. If using a version of the Connection Manager obtained from Defender 2.0.0 - 2.0.18, IBM strongly recommends upgrading. Instructions for upgrading can be found here .
Event History
Dec 8, 2025
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
CVE Published
via MITRE·09:51 PM
Data Sourced
via MITRE·09:51 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-64650?
CVE-2025-64650 has a medium severity level due to the potential exposure of sensitive user credentials.
2
How do I fix CVE-2025-64650?
To remediate CVE-2025-64650, upgrade IBM Storage Defender - Resiliency Service to version 2.0.19 or later.
3
What information is disclosed in CVE-2025-64650?
CVE-2025-64650 may disclose sensitive user credentials in log files, which can pose security risks.
4
Which versions of IBM Storage Defender - Resiliency Service are affected by CVE-2025-64650?
CVE-2025-64650 affects IBM Storage Defender - Resiliency Service versions 2.0.0 through 2.0.18.
5
Is a patch available for CVE-2025-64650?
Yes, a patch is available by upgrading to IBM Storage Defender - Resiliency Service version 2.0.19 or later.