CVE-2025-25048

IBM Jazz Foundation 7.0.2 through 7.0.2 iFix033, 7.0.3 through 7.0.3 iFix012, and 7.1.0 through 7.1.0 iFix002 could allow an authenticated user to upload files to the system due to improper neutralization of sequences that can resolve to a restricted directory.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
ibmCNA
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 14%
VendorProductVersion
ibmjazz_foundation
7.0.2
ibmjazz_foundation
7.0.2:ifix001
ibmjazz_foundation
7.0.2:ifix002
ibmjazz_foundation
7.0.2:ifix003
ibmjazz_foundation
7.0.2:ifix004
ibmjazz_foundation
7.0.2:ifix005
ibmjazz_foundation
7.0.2:ifix006
ibmjazz_foundation
7.0.2:ifix007
ibmjazz_foundation
7.0.2:ifix008a
ibmjazz_foundation
7.0.2:ifix009
ibmjazz_foundation
7.0.2:ifix010
ibmjazz_foundation
7.0.2:ifix011
ibmjazz_foundation
7.0.2:ifix012
ibmjazz_foundation
7.0.2:ifix013
ibmjazz_foundation
7.0.2:ifix014
ibmjazz_foundation
7.0.2:ifix016
ibmjazz_foundation
7.0.2:ifix017
ibmjazz_foundation
7.0.2:ifix018
ibmjazz_foundation
7.0.2:ifix020a
ibmjazz_foundation
7.0.2:ifix021
ibmjazz_foundation
7.0.2:ifix022
ibmjazz_foundation
7.0.2:ifix023
ibmjazz_foundation
7.0.2:ifix024
ibmjazz_foundation
7.0.2:ifix025
ibmjazz_foundation
7.0.2:ifix026a
ibmjazz_foundation
7.0.2:ifix027
ibmjazz_foundation
7.0.2:ifix028
ibmjazz_foundation
7.0.2:ifix029
ibmjazz_foundation
7.0.2:ifix030
ibmjazz_foundation
7.0.2:ifix031
ibmjazz_foundation
7.0.2:ifix032
ibmjazz_foundation
7.0.2:ifix033
ibmjazz_foundation
7.0.3
ibmjazz_foundation
7.0.3:ifix001
ibmjazz_foundation
7.0.3:ifix002
ibmjazz_foundation
7.0.3:ifix003
ibmjazz_foundation
7.0.3:ifix004
ibmjazz_foundation
7.0.3:ifix005
ibmjazz_foundation
7.0.3:ifix006
ibmjazz_foundation
7.0.3:ifix007
ibmjazz_foundation
7.0.3:ifix008
ibmjazz_foundation
7.0.3:ifix009
ibmjazz_foundation
7.0.3:ifix010
ibmjazz_foundation
7.0.3:ifix011
ibmjazz_foundation
7.0.3:ifix012
ibmjazz_foundation
7.1.0
ibmjazz_foundation
7.1.0:ifix001
ibmjazz_foundation
7.1.0:ifix002
𝑥
= Vulnerable software versions