← Back

CVE-2025-25048

nvd nist
Published: Sep 4, 2025Modified: Jan 9, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Exploitability: 2.8 / Impact: 3.6
Source: psirt@us.ibm.com (Secondary)

Description

IBM Jazz Foundation 7.0.2 through 7.0.2 iFix033, 7.0.3 through 7.0.3 iFix012, and 7.1.0 through 7.1.0 iFix002 could allow an authenticated user to upload files to the system due to improper neutralization of sequences that can resolve to a restricted directory.

Affected (48)

Products: Ibm: Jazz Foundation
1 product
Jazz Foundation
Configuration A
48 vulnerable
Vulnerable SoftwareAffected Versions
Ibm
Version 7.0.2
Version 7.0.2 ifix001
Version 7.0.2 ifix002
Version 7.0.2 ifix003
Version 7.0.2 ifix004
Version 7.0.2 ifix005
Version 7.0.2 ifix006
Version 7.0.2 ifix007
Version 7.0.2 ifix008a
Version 7.0.2 ifix009
Version 7.0.2 ifix010
Version 7.0.2 ifix011
Version 7.0.2 ifix012
Version 7.0.2 ifix013
Version 7.0.2 ifix014
Version 7.0.2 ifix016
Version 7.0.2 ifix017
Version 7.0.2 ifix018
Version 7.0.2 ifix020a
Version 7.0.2 ifix021
Version 7.0.2 ifix022
Version 7.0.2 ifix023
Version 7.0.2 ifix024
Version 7.0.2 ifix025
Version 7.0.2 ifix026a
Version 7.0.2 ifix027
Version 7.0.2 ifix028
Version 7.0.2 ifix029
Version 7.0.2 ifix030
Version 7.0.2 ifix031
Version 7.0.2 ifix032
Version 7.0.2 ifix033
Version 7.0.3
Version 7.0.3 ifix001
Version 7.0.3 ifix002
Version 7.0.3 ifix003
Version 7.0.3 ifix004
Version 7.0.3 ifix005
Version 7.0.3 ifix006
Version 7.0.3 ifix007
Version 7.0.3 ifix008
Version 7.0.3 ifix009
Version 7.0.3 ifix010
Version 7.0.3 ifix011
Version 7.0.3 ifix012
Version 7.1.0
Version 7.1.0 ifix001
Version 7.1.0 ifix002

References (1)

Source: psirt@us.ibm.com
PatchVendor Advisory

Timeline

No history available yet.