CVE-2005-1025 describes a sensitive information disclosure vulnerability in the FTP server of IBM AS/400 4.3 when operating in IFS mode. Remote attackers can leverage the RCMD and ADDLNK utilities to perform a symlink attack, specifically targeting the QSYS.LIB library, to gain unauthorized access to information. This vulnerability has a CVSS score of 5.0, indicating a medium severity. It is easily exploitable over the network with low attack complexity and requires no authentication, potentially leading to partial confidentiality impact. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. The vulnerability has garnered minimal community discussion or media coverage, suggesting it is not widely known or actively targeted.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.3CPE matchmatch criteria | cpe:2.3:h:ibm:iseries_as_400:4.3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.