IBM has issued urgent security advisories for two high-severity vulnerabilities (CVE-2025-0159, CVE-2025-0160) affecting its Storage Virtualize product suite, including SAN Volume Controller, Storwize, and FlashSystem families.
These flaws enable attackers to bypass authentication and execute arbitrary code remotely via the graphical user interface (GUI), posing significant risks to enterprise storage environments.
The vulnerabilities center on the RPCAdapter service, a component enabling remote procedure calls in IBM’s storage systems.
CVE-2025-0159 (CVSS 9.1) exploits improper authentication mechanisms in the RPCAdapter endpoint. Attackers can craft malicious HTTP requests containing specially formatted headers to bypass credential checks entirely.
This allows unauthorized access to administrative functions despite lacking valid tokens or certificates. Once authenticated via CVE-2025-0159, adversaries can leverage CVE-2025-0160 (CVSS 8.1) to execute arbitrary Java code.
The vulnerability arises from inadequate sandboxing in the RPCAdapter’s deserialization processes, permitting attackers to load malicious class files through manipulated RPC payloads.
This dual exploit chain enables full system compromise, including:
IBM confirms the command-line interface (CLI) remains unaffected, as the vulnerabilities are isolated to GUI components interacting with the RPCAdapter service.
The flaws impact nearly all IBM Storage Virtualize deployments running versions 8.5.0.0 through 8.7.2.1, including:
A detailed version matrix reveals risks across multiple code branches:
IBM mandates immediate upgrades to fixed code levels:
Notably, older branches require migration to supported versions like 8.6.x, reflecting IBM’s shift toward Long-Term Support (LTS) releases.
Administrators must download updates via IBM’s Fix Central portal. Platform-specific patches are available for FlashSystem 5000/5200/7200/9500 and SAN Volume Controller nodes.
The absence of viable workarounds heightens the urgency. While network segmentation and firewall rules could theoretically limit exposure, IBM stresses that patching remains the only definitive mitigation.
Are you from SOC/DFIR Teams? – Analyse Malware Incidents & get live Access with ANY.RUN -> Start Now for Free.
CISA's latest advisory for red teams warns critical infrastructure operators that security systems can fail…
Alice, the AI trust, safety, and security company formerly known as ActiveFence, has closed a…
SynkLoader is using Microsoft Teams conversations to turn routine IT support requests into a route…
ToxNetV2 is a Linux botnet that shows how artificial intelligence can move closer to real…
WhatsApp has confirmed that more than 1 billion people now use passkeys to log into…
ASOS US Sales LLC reported unauthorized access to customer accounts using credentials obtained from outside…