Path traversal in Apache Commons VFS - CVE-2025-27553

 

Path traversal in Apache Commons VFS - CVE-2025-27553

Published: March 27, 2025


Vulnerability identifier: #VU106082
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-27553
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing double dots, e.g. ".." in file names. A remote attacker can view files outside of the current scope.


Affected software

Apache Commons VFS
Netcool Operations Insight
Oracle Communications Unified Inventory Management
Oracle Middleware Common Libraries and Tools
IBM Cloud Pak for Business Automation
Oracle Communications EAGLE Element Management System
WebSphere eXtreme Scale
watsonx.data
IBM Cloud Pak for Watson AIOps
Oracle Financial Services Analytical Applications Infrastructure
Oracle Data Integrator
Oracle Communications Order and Service Management
openSUSE Leap
openEuler
Primavera Gateway
apache-commons-vfs (Red Hat package)
apache-commons-vfs
apache-commons-vfs-help
apache-commons-vfs-devel
apache-commons-vfs2-javadoc
apache-commons-vfs2
apache-commons-vfs2-examples
apache-commons-vfs2-ant

How to mitigate CVE-2025-27553

Install updates from vendor's website.

Apache Commons VFS - update to 2.10.0
Netcool Operations Insight - update to 1.6.15
watsonx.data - update to 2.2.1
IBM Cloud Pak for Watson AIOps - update to 4.10.0
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF007, 24.0.1-IF006, 25.0.0-IF003
apache-commons-vfs (Red Hat package) - update to 2.0-11.el7_9.1
apache-commons-vfs - addressed in versions 2.1-16, 2.10.0-1
apache-commons-vfs-help - addressed in versions 2.1-16, 2.10.0-1
apache-commons-vfs-devel - addressed in versions 2.1-16, 2.10.0-1
apache-commons-vfs2-javadoc - update to 2.10.0-150200.3.3.1
apache-commons-vfs2 - update to 2.10.0-150200.3.3.1
apache-commons-vfs2-examples - update to 2.10.0-150200.3.3.1
apache-commons-vfs2-ant - update to 2.10.0-150200.3.3.1
WebSphere eXtreme Scale - update to 8.6.1.6 PH68446

External References

Related Security Bulletins