CVE-2025-14754
HIGHCVSS 8.8/10EPSS 0.65%
Last modified
CVE-2025-14754 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. IBM Cloud Pak for Data 5.1.2 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.. EPSS estimates a 0.65% chance of exploitation in the next 30 days.
Description
IBM Cloud Pak for Data 5.1.2 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Cloud Pak For Data | 5.1.2 |
References
- https://www.ibm.com/support/pages/node/7287142Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-14754?
IBM Cloud Pak for Data 5.1.2 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.
How severe is CVE-2025-14754?
CVE-2025-14754 has a CVSS score of 8.8/10 (HIGH severity). The EPSS model estimates a 0.65% probability of exploitation in the next 30 days.
How do I fix CVE-2025-14754?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-14748A vulnerability was determined in Ningyuanda TC155 57.0.2.0.…5.4
- CVE-2025-14749A vulnerability was identified in Ningyuanda TC155 57.0.2.0.…8.8
- CVE-2025-1475The WPCOM Member plugin for WordPress is vulnerable to authe…9.8
- CVE-2025-14750The web application does not sufficiently verify inputs that…8.7
- CVE-2025-14751A low-privileged user can bypass account credentials without…8.7
- CVE-2025-14753IBM Cloud Pak for Data 5.1.2 could allow a remote attacker t…7.5
- CVE-2025-14755The Cost Calculator Builder plugin for WordPress is vulnerab…5.3
- CVE-2025-14756Command injection vulnerability was found in the admin inter…8.8
- CVE-2025-14757The Cost Calculator Builder plugin for WordPress is vulnerab…5.3
- CVE-2025-14758Incorrect configuration of replication security in the Maria…6.5
- CVE-2025-14759Missing cryptographic key commitment in the Amazon S3 Encryp…6
- CVE-2025-14760Missing cryptographic key commitment in the AWS SDK for C++ …6
Are you affected by CVE-2025-14754?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
