Information disclosure in Apache Commons VFS - CVE-2025-30474

 

Information disclosure in Apache Commons VFS - CVE-2025-30474

Published: March 27, 2025


Vulnerability identifier: #VU106083
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-30474
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to an error in the FtpFileObject class, that can expose passwords in clear text. A remote attacker can gain unauthorized access to sensitive information.


Affected software

Apache Commons VFS
Netcool Operations Insight
IBM Cloud Pak for Business Automation
WebSphere eXtreme Scale
watsonx.data
IBM Cloud Pak for Watson AIOps
openSUSE Leap
openEuler
apache-commons-vfs-help
apache-commons-vfs
apache-commons-vfs-devel
apache-commons-vfs2-javadoc
apache-commons-vfs2
apache-commons-vfs2-examples
apache-commons-vfs2-ant

How to mitigate CVE-2025-30474

Install updates from vendor's website.

Apache Commons VFS - update to 2.10.0
Netcool Operations Insight - update to 1.6.15
watsonx.data - update to 2.2.1
IBM Cloud Pak for Watson AIOps - update to 4.10.0
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF007, 24.0.1-IF006, 25.0.0-IF003
apache-commons-vfs-help - update to 2.10.0-1
apache-commons-vfs - update to 2.10.0-1
apache-commons-vfs-devel - update to 2.10.0-1
apache-commons-vfs2-javadoc - update to 2.10.0-150200.3.3.1
apache-commons-vfs2 - update to 2.10.0-150200.3.3.1
apache-commons-vfs2-examples - update to 2.10.0-150200.3.3.1
apache-commons-vfs2-ant - update to 2.10.0-150200.3.3.1
WebSphere eXtreme Scale - update to 8.6.1.6 PH68446

External References

Related Security Bulletins