{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2025-0159","assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","state":"PUBLISHED","assignerShortName":"ibm","dateReserved":"2024-12-31T19:09:07.200Z","datePublished":"2025-02-28T19:01:26.669Z","dateUpdated":"2026-02-26T18:29:06.038Z"},"containers":{"cna":{"affected":[{"cpes":["cpe:2.3:a:ibm:storage_virtualize:8.5.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:storage_virtualize:8.5.0.13:*:*:*:*:*:*:*","cpe:2.3:a:ibm:storage_virtualize:8.5.1.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:storage_virtualize:8.5.2.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:storage_virtualize:8.5.2.3:*:*:*:*:*:*:*","cpe:2.3:a:ibm:storage_virtualize:8.5.3.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:storage_virtualize:8.5.3.1:*:*:*:*:*:*:*","cpe:2.3:a:ibm:storage_virtualize:8.5.4.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:storage_virtualize:8.6.1.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:storage_virtualize:8.6.2.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:storage_virtualize:8.6.2.1:*:*:*:*:*:*:*","cpe:2.3:a:ibm:storage_virtualize:8.6.3.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:storage_virtualize:8.7.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:storage_virtualize:8.7.0.2:*:*:*:*:*:*:*","cpe:2.3:a:ibm:storage_virtualize:8.7.1.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:storage_virtualize:8.7.2.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:storage_virtualize:8.7.2.1:*:*:*:*:*:*:*"],"defaultStatus":"unaffected","product":"Storage Virtualize","vendor":"IBM","versions":[{"lessThanOrEqual":"8.5.0.13","status":"affected","version":"8.5.0.0","versionType":"semver"},{"status":"affected","version":"8.5.1.0"},{"lessThanOrEqual":"8.5.2.3","status":"affected","version":"8.5.2.0","versionType":"semver"},{"lessThanOrEqual":"8.5.3.1","status":"affected","version":"8.5.3.0","versionType":"semver"},{"status":"affected","version":"8.5.4.0"},{"lessThanOrEqual":"8.6.0.5","status":"affected","version":"8.6.0.0","versionType":"semver"},{"status":"affected","version":"8.6.1.0"},{"lessThanOrEqual":"8.6.2.1","status":"affected","version":"8.6.2.0","versionType":"semver"},{"status":"affected","version":"8.6.3.0"},{"status":"affected","version":"8.7.1.0"},{"lessThanOrEqual":"8.7.2.1","status":"affected","version":"8.7.2.0","versionType":"semver"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"IBM FlashSystem (IBM Storage Virtualize (8.5.0.0 through 8.5.0.13, 8.5.1.0, 8.5.2.0 through 8.5.2.3, 8.5.3.0 through 8.5.3.1, 8.5.4.0, 8.6.0.0 through 8.6.0.5, 8.6.1.0, 8.6.2.0 through 8.6.2.1, 8.6.3.0, 8.7.0.0 through 8.7.0.2, 8.7.1.0, 8.7.2.0 through 8.7.2.1) could allow a remote attacker to bypass RPCAdapter endpoint authentication by sending a specifically crafted HTTP request."}],"value":"IBM FlashSystem (IBM Storage Virtualize (8.5.0.0 through 8.5.0.13, 8.5.1.0, 8.5.2.0 through 8.5.2.3, 8.5.3.0 through 8.5.3.1, 8.5.4.0, 8.6.0.0 through 8.6.0.5, 8.6.1.0, 8.6.2.0 through 8.6.2.1, 8.6.3.0, 8.7.0.0 through 8.7.0.2, 8.7.1.0, 8.7.2.0 through 8.7.2.1) could allow a remote attacker to bypass RPCAdapter endpoint authentication by sending a specifically crafted HTTP request."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":9.1,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-288","description":"CWE-288 Authentication Bypass Using an Alternate Path or Channel","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm","dateUpdated":"2025-02-28T19:01:26.669Z"},"references":[{"tags":["vendor-advisory"],"url":"https://www.ibm.com/support/pages/node/7184182"}],"source":{"discovery":"UNKNOWN"},"title":"IBM FlashSystem authentication bypass","x_generator":{"engine":"Vulnogram 0.2.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"id":"CVE-2025-0159","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"total"}],"version":"2.0.3","timestamp":"2025-03-07T04:55:49.418162Z"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-02-26T18:29:06.038Z"}}]}}