PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-36398 IBM CVE debrief

IBM System Storage DS8A00 and DS8900F are vulnerable to an externally controlled filename issue, potentially allowing an authenticated user to read or modify another user's command history. This vulnerability affects specific versions of these systems, requiring authentication and having limited scope. System administrators and security teams should review and address the vulnerability, focusing on verifying affected product deployments and applying vendor-provided patches or updates. The vulnerability is rated as MEDIUM with a CVSS score of 5.4. Defenders should verify affected product deployments and review vendor guidance, considering compensating controls for command history access and monitoring for unauthorized access.

Vendor
IBM
Product
DS8A00 (R10.0 - R10.1)
CVSS
MEDIUM 5.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-19
Original CVE updated
2026-08-24
Advisory published
2026-08-19
Advisory updated
2026-08-24

Who should care

System administrators and security teams responsible for IBM System Storage DS8A00 and DS8900F systems, as well as users with access to these systems, should review and address the vulnerability. Operators and platform teams should also be aware of the potential impact on their systems and take necessary precautions.

Technical summary

IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an authenticated user to read or modify another user's command history due to an externally controlled filename. The vulnerability requires authentication and has limited scope.

Defensive priority

Medium priority due to authenticated user requirement and limited scope.

Recommended defensive actions

  • Inventory and verify affected IBM System Storage DS8A00 and DS8900F systems
  • Apply vendor-provided patches or updates
  • Monitor command history for unauthorized access
  • Implement compensating controls for command history access
  • Review relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

IBM System Storage DS8A00 and DS8900F are vulnerable to an externally controlled filename issue. Evidence from official CVE Program record and NVD vulnerability detail page supports the externally controlled filename issue. The vulnerability is rated as MEDIUM with a CVSS score of 5.4. Defenders should verify affected product deployments and review vendor guidance.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-36398 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-36398

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-36398 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-36398

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.