← Back

CVE-2025-36398

nvd nist
Published: Aug 19, 2026Modified: Aug 24, 2026

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.5
Source: psirt@us.ibm.com (Secondary)

Description

IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an authenticated user to read or modify another user's command history due to an externally controlled filename.

Affected (2)

2 products
Ds8900f Firmware
Ds8a00 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 89.40.83.0 to 89.44.25.0
Running on/withPlatform Versions
Ibm
Ds8900f
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 10.1.3.0 to 10.11.35.0
Running on/withPlatform Versions
Ibm
Ds8a00
All versions

References (1)

Source: psirt@us.ibm.com
Vendor Advisory

Timeline

No history available yet.