CVE-2025-36120

IBM Storage Virtualize 8.4, 8.5, 8.6, and 8.7 could allow an authenticated user to escalate their privileges in an SSH session due to incorrect authorization checks to access resources.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
ibmCNA
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 16%
VendorProductVersion
ibmstorage_virtualize
8.4.0.0 ≤
𝑥
< 8.4.0.18
ibmstorage_virtualize
8.5.0.0 ≤
𝑥
< 8.5.0.16
ibmstorage_virtualize
8.5.2.0 ≤
𝑥
≤ 8.5.2.3
ibmstorage_virtualize
8.6.0.0 ≤
𝑥
< 8.6.0.9
ibmstorage_virtualize
8.7.0.0 ≤
𝑥
< 8.7.0.6
ibmstorage_virtualize
8.7.3.0 ≤
𝑥
< 8.7.3.3
ibmstorage_virtualize
8.4.1.0
ibmstorage_virtualize
8.4.2.0
ibmstorage_virtualize
8.4.2.1
ibmstorage_virtualize
8.4.3.1
ibmstorage_virtualize
8.5.1.0
ibmstorage_virtualize
8.5.3.0
ibmstorage_virtualize
8.5.3.1
ibmstorage_virtualize
8.5.4.0
ibmstorage_virtualize
8.6.1.0
ibmstorage_virtualize
8.6.2.0
ibmstorage_virtualize
8.6.2.1
ibmstorage_virtualize
8.6.3.0
ibmstorage_virtualize
8.7.1.0
ibmstorage_virtualize
8.7.2.0
ibmstorage_virtualize
8.7.2.1
𝑥
= Vulnerable software versions