CVE-2025-36398

EUVD-2025-210743
IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an authenticated user to read or modify another user's command history due to an externally controlled filename.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.4 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 15.74%
Affected Products (NVD)
VendorProductVersion
ibmds8900f_firmware
89.40.83.0 ≤
𝑥
≤ 89.44.25.0
ibmds8a00_firmware
10.1.3.0 ≤
𝑥
≤ 10.11.35.0
𝑥
= Vulnerable software versions