CVE-2025-36120

Severity
8.8HIGH
EPSS
0.0%
top 87.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 18

Description

IBM Storage Virtualize 8.4, 8.5, 8.6, and 8.7 could allow an authenticated user to escalate their privileges in an SSH session due to incorrect authorization checks to access resources.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

NVDibm/storage_virtualize8.4.0.08.4.0.18+20
CVEListV5ibm/storage_virtualize4 versions+3

🔴Vulnerability Details

2
CVEList
IBM Storage Virtualize privilege escalation2025-08-18
GHSA
GHSA-qwfw-vm52-pf89: IBM Storage Virtualize 82025-08-18
CVE-2025-36120 (HIGH CVSS 8.8) | IBM Storage Virtualize 8.4 | cvebase.io