CVE-2025-36120

HIGH

IBM Storage Virtualize 8.4-8.7 - Authenticated Privilege Escalation via SSH Session

Title source: llm
STIX 2.1

Description

IBM Storage Virtualize 8.4, 8.5, 8.6, and 8.7 could allow an authenticated user to escalate their privileges in an SSH session due to incorrect authorization checks to access resources.

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory patch
https://www.ibm.com/support/pages/node/7240796

Scores

CVSS v3 8.8
EPSS 0.0006
EPSS Percentile 18.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-863
Status published
Products (16)
ibm/storage_virtualize 8.4.1.0
ibm/storage_virtualize 8.4.2.0
ibm/storage_virtualize 8.4.2.1
ibm/storage_virtualize 8.4.3.1
ibm/storage_virtualize 8.5.1.0
ibm/storage_virtualize 8.5.3.0
ibm/storage_virtualize 8.5.3.1
ibm/storage_virtualize 8.5.4.0
ibm/storage_virtualize 8.6.1.0
ibm/storage_virtualize 8.6.2.0
... and 6 more
Published Aug 18, 2025
Tracked Since Feb 18, 2026