CVE-2025-36120

EUVD-2025-25123
IBM Storage Virtualize 8.4, 8.5, 8.6, and 8.7 could allow an authenticated user to escalate their privileges in an SSH session due to incorrect authorization checks to access resources.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
ibmCNA
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 12%
Affected Products (NVD)
VendorProductVersion
ibmstorage_virtualize
8.4.0.0 ≤
𝑥
< 8.4.0.18
ibmstorage_virtualize
8.5.0.0 ≤
𝑥
< 8.5.0.16
ibmstorage_virtualize
8.5.2.0 ≤
𝑥
≤ 8.5.2.3
ibmstorage_virtualize
8.6.0.0 ≤
𝑥
< 8.6.0.9
ibmstorage_virtualize
8.7.0.0 ≤
𝑥
< 8.7.0.6
ibmstorage_virtualize
8.7.3.0 ≤
𝑥
< 8.7.3.3
ibmstorage_virtualize
8.4.1.0
ibmstorage_virtualize
8.4.2.0
ibmstorage_virtualize
8.4.2.1
ibmstorage_virtualize
8.4.3.1
ibmstorage_virtualize
8.5.1.0
ibmstorage_virtualize
8.5.3.0
ibmstorage_virtualize
8.5.3.1
ibmstorage_virtualize
8.5.4.0
ibmstorage_virtualize
8.6.1.0
ibmstorage_virtualize
8.6.2.0
ibmstorage_virtualize
8.6.2.1
ibmstorage_virtualize
8.6.3.0
ibmstorage_virtualize
8.7.1.0
ibmstorage_virtualize
8.7.2.0
ibmstorage_virtualize
8.7.2.1
𝑥
= Vulnerable software versions