SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2025-36398

MEDIUM · CVSS 5.4 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Authenticated users of IBM System Storage DS8A00 and DS8900F products may be able to read or modify other users' command histories due to a vulnerability involving externally controlled filenames. This could lead to unauthorized access to sensitive operational data and potential manipulation of system commands. Organizations using these IBM storage systems should prioritize addressing this issue to mitigate risks associated with user data exposure and integrity.

CVE
CVE-2025-36398
Severity
MEDIUM
CVSS
5.4
EPSS
0.19%

Original NVD Description

IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an authenticated user to read or modify another user's command history due to an externally controlled filename.

Related CVEs

Other vulnerabilities affecting the same vendor(s)