CVE-2025-36398

IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an authenticated user to read or modify another user's command history due to an externally controlled filename.
References
Link Resource
https://www.ibm.com/support/pages/node/7284322 Vendor Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:ibm:ds8900f_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:ds8900f:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:ibm:ds8a00_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:ds8a00:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-19 22:16

Updated : 2026-08-24 19:27


NVD link : CVE-2025-36398

Mitre link : CVE-2025-36398

CVE.ORG link : CVE-2025-36398


JSON object : View

Products Affected

ibm

  • ds8900f_firmware
  • ds8900f
  • ds8a00_firmware
  • ds8a00
CWE
CWE-73

External Control of File Name or Path