IBM Jazz Foundation 7.0.2 through 7.0.2 iFix033, 7.0.3 through 7.0.3 iFix012, and 7.1.0 through 7.1.0 iFix002 could allow an authenticated user to upload files to the system due to improper neutralization of sequences that can resolve to a restricted directory.
History

Thu, 04 Sep 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 04 Sep 2025 15:15:00 +0000

Type Values Removed Values Added
Description IBM Jazz Foundation 7.0.2 through 7.0.2 iFix033, 7.0.3 through 7.0.3 iFix012, and 7.1.0 through 7.1.0 iFix002 could allow an authenticated user to upload files to the system due to improper neutralization of sequences that can resolve to a restricted directory.
Title IBM Jazz Foundation path traversal
First Time appeared Ibm
Ibm jazz Foundation
Weaknesses CWE-23
CPEs cpe:2.3:a:ibm:jazz_foundation:7.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:jazz_foundation:7.0.2:ifix033:*:*:*:*:*:*
cpe:2.3:a:ibm:jazz_foundation:7.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:jazz_foundation:7.0.3:ifix012:*:*:*:*:*:*
cpe:2.3:a:ibm:jazz_foundation:7.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:jazz_foundation:7.1.0:ifix002:*:*:*:*:*:*
Vendors & Products Ibm
Ibm jazz Foundation
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published: 2025-09-04T15:06:15.076Z

Updated: 2025-09-04T15:16:08.257Z

Reserved: 2025-02-01T15:07:06.692Z

Link: CVE-2025-25048

cve-icon Vulnrichment

Updated: 2025-09-04T15:16:05.255Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-09-04T15:15:46.077

Modified: 2025-09-04T15:35:29.497

Link: CVE-2025-25048

cve-icon Redhat

No data.