Denial of Service Vulnerability in Oracle ZFS Storage Appliance Kit
CVE-2025-62478
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 21 October 2025
What is CVE-2025-62478?
A network-accessible vulnerability has been identified in Oracle's ZFS Storage Appliance Kit, specifically in the Object Store component. An attacker with high privileges can exploit this flaw via HTTP, leading to potential disruptions. Successful exploitation allows attackers to cause the appliance to hang or crash repeatedly, resulting in a denial of service. Organizations utilizing the affected version 8.8 are urged to assess their security posture and apply necessary mitigations as specified in Oracle's advisory.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Oracle ZFS Storage Appliance Kit 8.8
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved