PatchSiren cyber security CVE debrief
CVE-2025-36398 IBM CVE debrief
IBM System Storage DS8A00 and DS8900F are vulnerable to an externally controlled filename issue, potentially allowing an authenticated user to read or modify another user's command history. This vulnerability affects specific versions of these systems, requiring authentication and having limited scope. System administrators and security teams should review and address the vulnerability, focusing on verifying affected product deployments and applying vendor-provided patches or updates. The vulnerability is rated as MEDIUM with a CVSS score of 5.4. Defenders should verify affected product deployments and review vendor guidance, considering compensating controls for command history access and monitoring for unauthorized access.
- Vendor
- IBM
- Product
- DS8A00 (R10.0 - R10.1)
- CVSS
- MEDIUM 5.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-19
- Original CVE updated
- 2026-08-24
- Advisory published
- 2026-08-19
- Advisory updated
- 2026-08-24
Who should care
System administrators and security teams responsible for IBM System Storage DS8A00 and DS8900F systems, as well as users with access to these systems, should review and address the vulnerability. Operators and platform teams should also be aware of the potential impact on their systems and take necessary precautions.
Technical summary
IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an authenticated user to read or modify another user's command history due to an externally controlled filename. The vulnerability requires authentication and has limited scope.
Defensive priority
Medium priority due to authenticated user requirement and limited scope.
Recommended defensive actions
- Inventory and verify affected IBM System Storage DS8A00 and DS8900F systems
- Apply vendor-provided patches or updates
- Monitor command history for unauthorized access
- Implement compensating controls for command history access
- Review relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
IBM System Storage DS8A00 and DS8900F are vulnerable to an externally controlled filename issue. Evidence from official CVE Program record and NVD vulnerability detail page supports the externally controlled filename issue. The vulnerability is rated as MEDIUM with a CVSS score of 5.4. Defenders should verify affected product deployments and review vendor guidance.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-36398 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-36398
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-36398 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-36398
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.ibm.com/support/pages/node/7284322
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.