File Manipulation Vulnerability in IBM System Storage DS8A00 and DS8900F
CVE-2025-36398
5.4MEDIUM
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 19 August 2026
What is CVE-2025-36398?
A vulnerability exists in IBM System Storage DS8A00 and DS8900F that allows an authenticated user to read or alter another user's command history. This occurs due to an externally controlled filename, potentially enabling unauthorized data access and manipulation. Users are advised to review the provided advisories and apply necessary patches.
Affected Version(s)
DS8900F (R9.4) 89.40.83.0 <= 89.44.25.0
DS8A00 (R10.0 - R10.1) 10.1.3.0 <= 10.11.35.0