IBM Storage Virtualize 8.4, 8.5, 8.7, and 9.1 IKEv1 implementation allows remote attackers to obtain sensitive information from device memory via a Security Association (SA) negotiation request.
Advisories

No advisories yet.

Fixes

Solution

Remediation/Fixes IBM recommends that you fix this vulnerability by upgrading affected versions of IBM SAN Volume Controller, IBM Storwize V7000, IBM Storwize V5000, V5100 and V5000E, IBM FlashSystem 5000, 5100, 5200 and 5300, IBM FlashSystem 7200 and 7300, IBM FlashSystem 9100, 9200 and 9500 and IBM Storage Virtualize for Public Cloud to the code levels in the following table or higher using the download links for each product below the table. Affected Version(s) Fixed Version 8.4.0.0-8.4.0.9 8.4.0.10 8.4.1.0, 8.4.2.0-8.4.2.1, 8.4.3.0-8.4.3.1 8.5.0.7 8.5.0.0-8.5.0.6 8.5.0.7 8.5.1.0 8.5.2.0, 8.6.0.0 8.7.0.0-8.7.0.7 8.7.0.8 8.7.1.0, 8.7.2.0-8.7.2.1 9.1.0.2 9.1.0.0-9.1.0.1 9.1.0.2, 9.1.1.0 Latest IBM SAN Volume Controller Code Latest IBM Storwize V7000 Code Latest IBM Storwize V5000 and V5100 Code Latest IBM Storwize V5000E Code Latest IBM FlashSystem 9500 Code Latest IBM FlashSystem 9100 Family Code Latest IBM FlashSystem 9200 Code Latest IBM FlashSystem 7300 Code Latest IBM FlashSystem 7200 Code Latest IBM FlashSystem 5000 and 5200 Code Latest IBM FlashSystem 5300 Code Latest IBM Storage Virtualize for Public Cloud


Workaround

No workaround given by the vendor.

History

Mon, 17 Nov 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 17 Nov 2025 21:00:00 +0000

Type Values Removed Values Added
Description IBM Storage Virtualize 8.4, 8.5, 8.7, and 9.1 IKEv1 implementation allows remote attackers to obtain sensitive information from device memory via a Security Association (SA) negotiation request.
Title IBM Storage Virtualize Information Disclosure
First Time appeared Ibm
Ibm storage Virtualize
Weaknesses CWE-244
CPEs cpe:2.3:a:ibm:storage_virtualize:8.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:storage_virtualize:8.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:storage_virtualize:8.7:*:*:*:*:*:*:*
cpe:2.3:a:ibm:storage_virtualize:9.1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm storage Virtualize
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2025-11-17T20:57:45.516Z

Reserved: 2025-04-15T21:16:17.124Z

Link: CVE-2025-36118

cve-icon Vulnrichment

Updated: 2025-11-17T20:57:37.854Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-17T21:15:57.450

Modified: 2025-11-18T14:06:29.817

Link: CVE-2025-36118

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.