Vulnerability in IBM System Storage DS8000 Affects Backup Integrity
CVE-2025-36192

6.7MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
26 December 2025

What is CVE-2025-36192?

A vulnerability in IBM System Storage DS8000 allows a local user with authorized update permissions to bypass necessary authorization checks. This security gap could enable the deletion or corruption of backups, undermining the integrity of backup data. The weakness lies within the IBM Safeguarded Copy and GDPS Logical corruption protection mechanisms, which fail to restrict user actions adequately.

Affected Version(s)

DS8900F ( R9.4) 89.40.83.0

DS8900F ( R9.4) 89.42.18.0

DS8900F ( R9.4) 89.44.5.0

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-36192 : Vulnerability in IBM System Storage DS8000 Affects Backup Integrity