CVE-2025-66838: Medium severity Software AG Aris vulnerability
In Aris v10.0.23.0.3587512 and before, the file upload functionality does not enforce any rate limiting or throttling, allowing users to upload files at an unrestricted rate. An attacker can exploit this behavior to rapidly upload a large volume of files, potentially leading to resource exhaustion such as disk space depletion, increased server load, or degraded performance
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66838?
The severity of CVE-2025-66838 is significant due to the potential for resource exhaustion resulting from unrestricted file uploads.
How do I fix CVE-2025-66838?
To fix CVE-2025-66838, implement rate limiting or throttling mechanisms to restrict the number of file uploads a user can perform in a given timeframe.
What systems are affected by CVE-2025-66838?
CVE-2025-66838 affects Software AG Aris versions up to and including 10.0.23.0.3587512.
What is the potential impact of CVE-2025-66838?
The potential impact of CVE-2025-66838 includes resource exhaustion and possible denial of service due to excessive file uploads.
Can CVE-2025-66838 lead to data breaches?
While CVE-2025-66838 primarily poses a denial of service risk, unchecked file uploads could potentially be exploited in a broader attack context.