CVE-2025-36398
Received
Received - Intake
IBM DS8000 Command History Access Vulnerability
Vulnerability report for CVE-2025-36398, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-19
Last updated on: 2026-08-19
Assigner: IBM Corporation
Description
Description
IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an authenticated user to read or modify another user's command history due to an externally controlled filename.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ibm | system_storage_ds8a00 | From 10.1.3.0 (inc) to 10.11.35.0 (inc) |
| ibm | ds8900f | From 89.40.83.0 (inc) to 89.44.25.0 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-73 | The product allows user input to control or influence paths or file names that are used in filesystem operations. |