CVE-2025-36398
Analyzed Analyzed - Analysis Complete

IBM DS8000 Command History Access Vulnerability

Vulnerability report for CVE-2025-36398, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-24

Assigner: IBM Corporation

Description

IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an authenticated user to read or modify another user's command history due to an externally controlled filename.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-24
Generated
2026-09-09
AI Q&A
2026-08-20
EPSS Evaluated
2026-09-07
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
ibm ds8900f_firmware From 89.40.83.0 (inc) to 89.44.25.0 (inc)
ibm ds8a00_firmware From 10.1.3.0 (inc) to 10.11.35.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-73 The product allows user input to control or influence paths or file names that are used in filesystem operations.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows an authenticated user to read or modify another user's command history in IBM System Storage DS8A00 and DS8900F products due to an externally controlled filename.

Detection Guidance

This vulnerability involves command history exposure in IBM System Storage DS8A00 and DS8900F. Detection requires checking for unauthorized access to user command histories. Review system logs for unusual file access patterns in command history directories. Inspect user permissions on these files. No specific commands are provided in the context.

Impact Analysis

An attacker with access could view sensitive commands executed by other users or alter command history, potentially leading to unauthorized actions or data exposure.

Compliance Impact

This vulnerability could compromise data integrity and confidentiality, potentially violating compliance requirements for GDPR, HIPAA, or other regulations that mandate access controls and audit logging.

Mitigation Strategies

Update IBM System Storage DS8A00 to version 10.11.36.0 or later and IBM DS8900F to version 89.44.26.0 or later to address the vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-36398. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart