Severity
4.4MEDIUM
EPSS
0.0%
top 90.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 25
Latest updateDec 3

Description

IBM Spectrum Protect Backup-Archive Client and IBM Spectrum Protect for Virtual Environments 7.1 and 8.1 creates directories/files in the CIT sub directory that are read/writable by everyone. IBM X-Force ID: 155551.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:NExploitability: 1.8 | Impact: 2.5

Affected Packages3 packages

NVDibm/spectrum_protect7.1.0.07.1.8.5+1

🔴Vulnerability Details

3
GHSA
webpack-dev-server users' source code may be stolen when they access a malicious web site with non-Chromium based browser2025-06-04
GHSA
GHSA-9v97-r4gf-gp7x: IBM Spectrum Protect Backup-Archive Client and IBM Spectrum Protect for Virtual Environments 72022-05-24
CVEList
CVE-2018-2025: IBM Spectrum Protect Backup-Archive Client and IBM Spectrum Protect for Virtual Environments 72019-11-25

💥Exploits & PoCs

1
Exploit-DB
MobileDetect 2.8.31 - Cross-Site Scripting (XSS)2025-12-03

📋Vendor Advisories

13
CISA
Paessler PRTG Network Monitor Local File Inclusion Vulnerability2025-02-04
Microsoft
An out of bounds read was discovered in systemd-journald in the way it parses log messages that terminate with a colon ':'. A local attacker can use this flaw to disclose process memory data. Versions2019-01-08
Microsoft
cairo 1.16.0 in cairo_ft_apply_variations() in cairo-ft-font.c would free memory using a free function incompatible with WebKit's fastMalloc leading to an application crash with a "free(): invalid poi2018-12-11
Microsoft
The SingleDocParser::HandleFlowMap function in yaml-cpp (aka LibYaml-C++) 0.6.2 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted YAML file.2018-12-11
Microsoft
An issue was discovered in lxml before 4.2.5. lxml/html/clean.py in the lxml.html.clean module does not remove javascript: URLs that use escaping allowing a remote attacker to conduct XSS attacks as d2018-12-11
CVE-2018-2025 (MEDIUM CVSS 4.4) | IBM Spectrum Protect Backup-Archive | cvebase.io