Sensitive User Credential Disclosure in IBM Storage Defender by IBM
CVE-2025-64650

6.5MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
8 December 2025

What is CVE-2025-64650?

IBM Storage Defender's Resiliency Service versions 2.0.0 through 2.0.18 are susceptible to a vulnerability that may lead to sensitive user credentials being disclosed in log files. This oversight can expose critical information and compromise the security of user accounts. It is imperative for users of the affected versions to apply available patches promptly to mitigate risks. For detailed information and fixes, consult the advisory from IBM.

Affected Version(s)

Storage Defender - Resiliency Service 2.0.0 <= 2.0.18

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-64650 : Sensitive User Credential Disclosure in IBM Storage Defender by IBM