Denial of Service Vulnerability in Oracle ZFS Storage Appliance Kit by Oracle Systems
CVE-2025-53046

4.9MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 October 2025

What is CVE-2025-53046?

A vulnerability in the Oracle ZFS Storage Appliance Kit allows a high-privileged attacker with network access via HTTP to exploit the system. When successfully attacked, this vulnerability can cause the appliance to hang or repeatedly crash, effectively leading to a Denial of Service, impacting the availability of critical services. The affected version is 8.8, and users are urged to implement necessary security measures to safeguard their installations.

Affected Version(s)

Oracle ZFS Storage Appliance Kit 8.8

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.