IBM Common Cryptographic Architecture (CCA) 7.5.52 and 8.4.82 could allow an unauthenticated user to execute arbitrary commands with elevated privileges on the system.

Project Subscriptions

Vendors Products
Common Cryptographic Architecture Subscribe
Advisories

No advisories yet.

Fixes

Solution

IBM strongly recommends addressing the vulnerability now by upgrading:  Product(s)Fixed Version(s)CCA 7 MTM for 4769 7.5.53 CCA 8 MTM for 4770 8.4.84 IBM 4769 Developers Toolkit 7.5.53


Workaround

No workaround given by the vendor.

History

Wed, 04 Feb 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Ibm
Ibm common Cryptographic Architecture
CPEs cpe:2.3:a:ibm:common_cryptographic_architecture:7.5.52:*:*:*:*:aix:*:*
cpe:2.3:a:ibm:common_cryptographic_architecture:7.5.52:*:*:*:*:ibm_i:*:*
cpe:2.3:a:ibm:common_cryptographic_architecture:7.5.52:*:*:*:*:linux:x86:*
cpe:2.3:a:ibm:common_cryptographic_architecture:7.5.52:*:*:*:*:powerlinux:*:*
cpe:2.3:a:ibm:common_cryptographic_architecture:8.4.82:*:*:*:*:aix:*:*
cpe:2.3:a:ibm:common_cryptographic_architecture:8.4.82:*:*:*:*:ibm_i:*:*
cpe:2.3:a:ibm:common_cryptographic_architecture:8.4.82:*:*:*:*:linux:x86:*
cpe:2.3:a:ibm:common_cryptographic_architecture:8.4.82:*:*:*:*:powerlinux:*:*
Vendors & Products Ibm
Ibm common Cryptographic Architecture

Wed, 04 Feb 2026 20:45:00 +0000

Type Values Removed Values Added
Description IBM Common Cryptographic Architecture (CCA) 7.5.52 and 8.4.82 could allow an unauthenticated user to execute arbitrary commands with elevated privileges on the system.
Title IBM Common Cryptographic Architecture Arbitrary Command Execution
Weaknesses CWE-250
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-02-04T20:46:57.901Z

Reserved: 2025-11-18T19:19:10.873Z

Link: CVE-2025-13375

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-02-04T21:15:57.213

Modified: 2026-02-04T21:15:57.213

Link: CVE-2025-13375

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses