IBM DS8A00和IBM DS8900F都是美国国际商业机器(IBM)公司的一款企业存储系统。 IBM DS8A00 R10.1 10.10.106.0版本和IBM DS8900F R9.4 89.40.83.089.42.18.089.44.5.0版本存在安全漏洞,该漏洞源于IBM Safeguarded Copy和GDPS Logical corruption保护机制中缺少授权,可能导致本地用户删除或损坏备份。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| IBM | DS8A00( R10.1) | 10.10.106.0 |
cpe:2.3:o:ibm:ds8900f_firmware:89.40.83.0:*:*:*:*:*:*:*
|
|
| IBM | DS8A00 ( R10.0) | 10.1.3.0 | - |
|
| IBM | DS8900F ( R9.4) | 89.40.83.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-13915 | 9.8 CRITICAL | Authentication bypass in IBM API Connect |
| CVE-2025-12771 | 7.8 HIGH | IBM Concert Software Improper Restriction of Operations within the Bounds of a Memory Buff |
| CVE-2025-64645 | 7.7 HIGH | Multiple Vulnerabilities in IBM Concert Software. |
| CVE-2025-1721 | 5.9 MEDIUM | BM Concert Software Improper Clearing of Heap Memory Before Release. |
| CVE-2025-36230 | 5.4 MEDIUM | XSS in IBM Aspera Faspex |
| CVE-2025-14687 | 4.3 MEDIUM | Client-Side Enforcement of Server-Side Security in IBM Db2 Intelligence Center |
| CVE-2025-36228 | 3.8 LOW | Incorrect Execution-Assigned Permissions in IBM Aspera Faspex |
| CVE-2025-36229 | 3.1 LOW | Exposure of Sensitive System Information to an Unauthorized Control Sphere in IBM Aspera F |
No comments yet