Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-36255— DS8900F and DS8A00 Privilege Escalation

CVSS 7.5 · High EPSS 0.25% · P17

Possible ATT&CK Techniques 1AI

T1136 · Create Account

Affected Version Matrix 2

VendorProductVersion RangeStatus
IBMDS8900F ( R9.4)89.40.83.0≤ 89.44.25.0affected
IBMDS8A00( R10.0 - R10.1 )10.1.3.0≤ 10.11.35.0affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-36255

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
DS8900F and DS8A00 Privilege Escalation
Source: CVE Program / CVE List V5
Vulnerability Description
IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an authenticated user to create a user with privileged user roles due to improper privileged defined with unsafe actions.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
特权定义了不安全动作
Source: CVE Program / CVE List V5
Vulnerability Title
IBM System Storage DS8A00 权限许可和访问控制问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
IBM System Storage DS8A00是美国IBM公司的一款企业级数据存储系统。 IBM System Storage DS8A00 10.1.3.0版本至10.11.35.0版本和IBM DS8900F 89.40.83.0版本至89.44.25.0版本存在安全漏洞,该漏洞源于权限定义不当且存在不安全操作,可能允许已认证用户创建具有特权用户角色的用户。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
IBMDS8A00( R10.0 - R10.1 ) 10.1.3.0 ~ 10.11.35.0 cpe:2.3:o:ibm:system_storage_ds8A00:10.1.3.0:*:*:*:*:*:*:*
IBMDS8900F ( R9.4) 89.40.83.0 ~ 89.44.25.0 cpe:2.3:o:ibm:system_storage_ds8900f:89.40.83.0:*:*:*:*:*:*:*

II. Public POCs for CVE-2025-36255

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-36255

登录查看更多情报信息。

Same Patch Batch · IBM · 2026-08-19 · 107 CVEs total

CVE-2026-150689.9 CRITICALVulnerabilities in IBM AIX and PowerVM VIOS
CVE-2026-168169.9 CRITICALVulnerabilities in IBM AIX and PowerVM VIOS
CVE-2026-168349.8 CRITICALVulnerabilities in IBM AIX and PowerVM VIOS
CVE-2026-169199.8 CRITICALVulnerabilities in IBM AIX and PowerVM VIOS
CVE-2026-169179.8 CRITICALVulnerabilities in IBM AIX and PowerVM VIOS
CVE-2026-168649.8 CRITICALVulnerabilities in IBM AIX and PowerVM VIOS
CVE-2026-169139.8 CRITICALVulnerabilities in IBM AIX and PowerVM VIOS
CVE-2026-168629.8 CRITICALVulnerabilities in IBM AIX and PowerVM VIOS
CVE-2026-168949.8 CRITICALVulnerabilities in IBM AIX and PowerVM VIOS
CVE-2026-166569.8 CRITICALVulnerabilities in IBM AIX and PowerVM VIOS
CVE-2026-168829.8 CRITICALVulnerabilities in IBM AIX and PowerVM VIOS
CVE-2026-168859.8 CRITICALVulnerabilities in IBM AIX and PowerVM VIOS
CVE-2026-168459.8 CRITICALVulnerabilities in IBM AIX and PowerVM VIOS
CVE-2026-168729.8 CRITICALVulnerabilities in IBM AIX and PowerVM VIOS
CVE-2026-168409.8 CRITICALVulnerabilities in IBM AIX and PowerVM VIOS
CVE-2026-166879.6 CRITICALPower System Buffer Overflow
CVE-2026-169039.6 CRITICALVulnerabilities in IBM AIX and PowerVM VIOS
CVE-2026-168359.6 CRITICALPower System Improper Certificate Validation
CVE-2026-168399.4 CRITICALVulnerabilities in IBM AIX and PowerVM VIOS
CVE-2026-168229.3 CRITICALVulnerabilities in IBM AIX and PowerVM VIOS

Showing top 20 of 107 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2025-36255

No comments yet


Leave a comment