CVE-2025-36398
Received Received - Intake

IBM DS8000 Command History Access Vulnerability

Vulnerability report for CVE-2025-36398, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-19

Assigner: IBM Corporation

Description

IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an authenticated user to read or modify another user's command history due to an externally controlled filename.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-19
Generated
2026-08-20
AI Q&A
2026-08-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
ibm system_storage_ds8a00 From 10.1.3.0 (inc) to 10.11.35.0 (inc)
ibm ds8900f From 89.40.83.0 (inc) to 89.44.25.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-73 The product allows user input to control or influence paths or file names that are used in filesystem operations.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows an authenticated user to read or modify another user's command history in IBM System Storage DS8A00 and DS8900F products due to an externally controlled filename.

Impact Analysis

An attacker with access could view sensitive commands executed by other users or alter command history, potentially leading to unauthorized actions or data exposure.

Compliance Impact

This vulnerability could compromise data integrity and confidentiality, potentially violating compliance requirements for GDPR, HIPAA, or other regulations that mandate access controls and audit logging.

Mitigation Strategies

Update IBM System Storage DS8A00 to version 10.11.36.0 or later and IBM DS8900F to version 89.44.26.0 or later to address the vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-36398. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart