Vulnerability Description
In Aris v10.0.23.0.3587512 and before, the file upload functionality does not enforce any rate limiting or throttling, allowing users to upload files at an unrestricted rate. An attacker can exploit this behavior to rapidly upload a large volume of files, potentially leading to resource exhaustion such as disk space depletion, increased server load, or degraded performance
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Softwareag | Aris | <= 10.0.23.0.3587512 |
Related Weaknesses (CWE)
References
- https://github.com/saykino/CVE-2025-66838/Third Party Advisory
- https://www.softwareag.com/Product
FAQ
What is CVE-2025-66838?
CVE-2025-66838 is a vulnerability with a CVSS score of 6.5 (MEDIUM). In Aris v10.0.23.0.3587512 and before, the file upload functionality does not enforce any rate limiting or throttling, allowing users to upload files at an unrestricted rate. An attacker can exploit t...
How severe is CVE-2025-66838?
CVE-2025-66838 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-66838?
Check the references section above for vendor advisories and patch information. Affected products include: Softwareag Aris.