Information disclosure in Apache Commons VFS - CVE-2025-30474
Published: March 27, 2025
Vulnerability identifier: #VU106083
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-30474
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to an error in the FtpFileObject class, that can expose passwords in clear text. A remote attacker can gain unauthorized access to sensitive information.
Affected software
Apache Commons VFS
Netcool Operations Insight
IBM Cloud Pak for Business Automation
WebSphere eXtreme Scale
watsonx.data
IBM Cloud Pak for Watson AIOps
openSUSE Leap
openEuler
apache-commons-vfs-help
apache-commons-vfs
apache-commons-vfs-devel
apache-commons-vfs2-javadoc
apache-commons-vfs2
apache-commons-vfs2-examples
apache-commons-vfs2-ant
Netcool Operations Insight
IBM Cloud Pak for Business Automation
WebSphere eXtreme Scale
watsonx.data
IBM Cloud Pak for Watson AIOps
openSUSE Leap
openEuler
apache-commons-vfs-help
apache-commons-vfs
apache-commons-vfs-devel
apache-commons-vfs2-javadoc
apache-commons-vfs2
apache-commons-vfs2-examples
apache-commons-vfs2-ant
How to mitigate CVE-2025-30474
Install updates from vendor's website.
Apache Commons VFS - update to 2.10.0
Netcool Operations Insight - update to 1.6.15
watsonx.data - update to 2.2.1
IBM Cloud Pak for Watson AIOps - update to 4.10.0
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF007, 24.0.1-IF006, 25.0.0-IF003
apache-commons-vfs-help - update to 2.10.0-1
apache-commons-vfs - update to 2.10.0-1
apache-commons-vfs-devel - update to 2.10.0-1
apache-commons-vfs2-javadoc - update to 2.10.0-150200.3.3.1
apache-commons-vfs2 - update to 2.10.0-150200.3.3.1
apache-commons-vfs2-examples - update to 2.10.0-150200.3.3.1
apache-commons-vfs2-ant - update to 2.10.0-150200.3.3.1
WebSphere eXtreme Scale - update to 8.6.1.6 PH68446
Netcool Operations Insight - update to 1.6.15
watsonx.data - update to 2.2.1
IBM Cloud Pak for Watson AIOps - update to 4.10.0
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF007, 24.0.1-IF006, 25.0.0-IF003
apache-commons-vfs-help - update to 2.10.0-1
apache-commons-vfs - update to 2.10.0-1
apache-commons-vfs-devel - update to 2.10.0-1
apache-commons-vfs2-javadoc - update to 2.10.0-150200.3.3.1
apache-commons-vfs2 - update to 2.10.0-150200.3.3.1
apache-commons-vfs2-examples - update to 2.10.0-150200.3.3.1
apache-commons-vfs2-ant - update to 2.10.0-150200.3.3.1
WebSphere eXtreme Scale - update to 8.6.1.6 PH68446
External References
Related Security Bulletins
- Multiple vulnerabilities in Apache Commons VFS
- SUSE update for apache-commons-vfs2
- openEuler 24.03 LTS update for apache-commons-vfs
- openEuler 24.03 LTS SP1 update for apache-commons-vfs
- Multiple vulnerabilities in IBM Cloud Pak for AIOps
- Multiple vulnerabilities in IBM watsonx.data
- Multiple vulnerabilities in IBM WebSphere Extreme Scale
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation