GPU VulnDB

Database/Control plane, storage & DevOps

Oracle ZFS Storage Appliance Kit: HTTP-reachable flaw in Block Storage allows full appliance takeover

CVSS 7.2CVE-2025-62290Control plane, storage & DevOpscurated

Impact

Oracle describes this as an easily exploitable flaw that lets a high-privileged attacker with HTTP access take over the ZFS Storage Appliance Kit, with high confidentiality, integrity and availability impact. Where a ZFS appliance backs a training or inference fleet, that is control of the dataset and checkpoint store for every tenant on it - read, tamper or deny. Loss of availability on a shared NAS does not stop at one node: jobs across the cluster stall together, and a storage outage is not something a single node drain works around. The record gives no technical mechanism beyond the affected component.

Who can reach it

Network access to the appliance over HTTP, holding high privileges on the appliance (an administrative account or equivalent). Not an unauthenticated path, so exposure depends on who can reach the management interface and who holds admin credentials.

What to do

Apply the fix from the Oracle October 2025 Critical Patch Update for the ZFS Storage Appliance Kit 8.8. Patching an appliance controller means a service window on the storage head - on a single-head deployment the share goes away for the duration, and on a clustered pair you take one head at a time and accept degraded failover in between. Oracle does not publish a workaround; restricting network reach to the appliance management interface narrows the exposure in the meantime.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.