In Aris v10.0.23.0.3587512 and before, the file upload functionality does not enforce any rate limiting or throttling, allowing users to upload files at an unrestricted rate. An attacker can exploit this behavior to rapidly upload a large volume of files, potentially leading to resource exhaustion such as disk space depletion, increased server load, or degraded performance
References
| Link | Resource |
|---|---|
| https://github.com/saykino/CVE-2025-66838/ | Third Party Advisory |
| https://www.softwareag.com/ | Product |
Configurations
History
21 Jan 2026, 22:06
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/saykino/CVE-2025-66838/ - Third Party Advisory | |
| References | () https://www.softwareag.com/ - Product | |
| CPE | cpe:2.3:a:softwareag:aris:*:*:*:*:*:*:*:* | |
| First Time |
Softwareag aris
Softwareag |
07 Jan 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
| CWE | CWE-770 |
07 Jan 2026, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-07 16:15
Updated : 2026-01-21 22:06
NVD link : CVE-2025-66838
Mitre link : CVE-2025-66838
CVE.ORG link : CVE-2025-66838
JSON object : View
Products Affected
softwareag
- aris
CWE
CWE-770
Allocation of Resources Without Limits or Throttling
