CVE-2025-25048
published 2025-09-04CVE-2025-25048: IBM Jazz Foundation 7.0.2 through 7.0.2 iFix033, 7.0.3 through 7.0.3 iFix012, and 7.1.0 through 7.1.0 iFix002 could allow an authenticated user to upload files…
PriorityP433medium6.5CVSS 3.1
AVNACLPRNUIRSUCNIHAN
EPSS
0.31%
22.4th percentile
IBM Jazz Foundation 7.0.2 through 7.0.2 iFix033, 7.0.3 through 7.0.3 iFix012, and 7.1.0 through 7.1.0 iFix002 could allow an authenticated user to upload files to the system due to improper neutralization of sequences that can resolve to a restricted directory.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | jazz_foundation | — | — |
| ibm | jazz_foundation | — | — |
| ibm | jazz_foundation | — | — |
| ibm | jazz_foundation | 7.0.2 – 7.0.2 iFix033 | — |
| ibm | jazz_foundation | 7.0.3 – 7.0.3 iFix012 | — |
| ibm | jazz_foundation | 7.1.0 – 7.1.0 iFix002 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-09-04
Published