File Upload Vulnerability in IBM Jazz Foundation Products
CVE-2025-25048

6.5MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
4 September 2025

What is CVE-2025-25048?

The IBM Jazz Foundation contains a vulnerability that permits authenticated users to upload files to restricted directories. This occurs due to insufficient validation of file paths, which can lead to unauthorized access or manipulation of sensitive data. It is crucial for organizations utilizing affected versions to apply recommended patches to safeguard their systems from potential exploitation.

Affected Version(s)

Jazz Foundation 7.0.2 <= 7.0.2 iFix033

Jazz Foundation 7.0.3 <= 7.0.3 iFix012

Jazz Foundation 7.1.0 <= 7.1.0 iFix002

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.