CVE-2025-0159: IBM Storage Virtualize

Critical severity, CVSS 9.1. EPSS: 0.9% chance of exploitation in the next 30 days.

IBM FlashSystem (IBM Storage Virtualize (8.5.0.0 through 8.5.0.13, 8.5.1.0, 8.5.2.0 through 8.5.2.3, 8.5.3.0 through 8.5.3.1, 8.5.4.0, 8.6.0.0 through 8.6.0.5, 8.6.1.0, 8.6.2.0 through 8.6.2.1, 8.6.3.0, 8.7.0.0 through 8.7.0.2, 8.7.1.0, 8.7.2.0 through 8.7.2.1) could allow a remote attacker to bypass RPCAdapter endpoint authentication by sending a specifically crafted HTTP request.

Affected products

  • IBM Storage Virtualize: from 8.5, before 8.5.0.14 (fixed in 8.5.0.14); from 8.5.2.0, up to and including 8.5.2.3; from 8.6.0.0, before 8.6.0.6 (fixed in 8.6.0.6); from 8.7.0.0, before 8.7.0.3 (fixed in 8.7.0.3); version 8.5.1.0 only; version 8.5.3.0 only; …

Published 2025-02-28. Last modified 2026-06-17.