CVE-2025-62290

7.2

Oracle · ZFS Storage Appliance Kit

A high-privilege vulnerability exists in the Oracle ZFS Storage Appliance Kit block storage component, allowing for full system compromise via network-based HTTP access.

Executive summary

A critical vulnerability in Oracle ZFS Storage Appliance Kit 8.8 allows an authenticated attacker with high privileges to achieve a full system takeover.

Vulnerability

This is a high-severity vulnerability within the block storage component of the appliance. It requires an attacker to possess high-level administrative privileges and network access to the HTTP interface to successfully execute a total system takeover.

Business impact

Successful exploitation of this vulnerability results in a complete compromise of the Oracle ZFS Storage Appliance Kit, leading to a total loss of confidentiality, integrity, and availability. Given the CVSS 3.1 base score of 7.2, this flaw poses a significant risk to data stored on the appliance and could facilitate unauthorized access to sensitive information or disruptive system downtime for business operations.

Remediation

Immediate Action: Consult the Oracle Critical Patch Update for October 2025 to identify and apply the specific security patch for the ZFS Storage Appliance Kit version 8.8.

Proactive Monitoring: Review administrative access logs for unauthorized HTTP requests or unusual configuration changes originating from privileged accounts.

Compensating Controls: Restrict network access to the management interface of the ZFS Storage Appliance to trusted administrative subnets only.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations utilizing Oracle ZFS Storage Appliance Kit version 8.8 must prioritize the application of the October 2025 security updates. Because this vulnerability allows for complete system takeover, administrators should verify that only authorized personnel have high-level access to the appliance management interface until patches are successfully deployed.

More Oracle CVEs

Sources