CVE-2025-36254
IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an attacker to bypass security authentication due to improperly encoding of DSCLI command output to obtain sensitive information or cause a denial of service.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.4
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H
- EPSS probability
- 0.36%
- CWE
- CWE-116
- Published
- 2026-08-19
- Last modified
- 2026-08-20
Affected products
- IBM DS8A00 (R10.0 - R10.1)
- IBM DS8900F (R9.4)
Weakness type
Related vulnerabilities
- CVE-2026-20245 — Cisco Catalyst SD-WAN Controller Authenticated Privilege Escalation Vulnerability
- CVE-2025-55730 — XWiki Remote Macros vulnerable to remote code execution using the confluence paste code macro
- CVE-2025-55729 — XWiki Remote Macros vulnerable to remote code execution using the ConfluenceLayoutSection macro
- CVE-2026-22792 — 5ire vulnerable to Remote Code Execution (RCE)
- CVE-2025-59936 — get-jwks poisoned JWKS cache allows post-fetch issuer validation bypass
- CVE-2025-59158 — Coolify has Stored XSS in Project Name
- CVE-2026-32754 — FreeScout: Stored XSS via Unescaped Email Template Rendering ({!! $thread->body !!})
- CVE-2025-40547 — SolarWinds Serv-U Logic Abuse - Remote Code Execution Vulnerability