Information Disclosure in IBM PowerVM Hypervisor
CVE-2025-36238

6MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
2 February 2026

What is CVE-2025-36238?

A vulnerability exists in IBM PowerVM Hypervisor that could permit local users with administrative privileges to access sensitive information from a Virtual Trusted Platform Module (TPM). This occurs through specific PowerVM service procedures, which may lead to potential data exposure.

Affected Version(s)

PowerVM Hypervisor FW1110.00

PowerVM Hypervisor FW1060.00

PowerVM Hypervisor FW950.00

References

CVSS V3.1

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.