Description
IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an authenticated user to read or modify another user's command history due to an externally controlled filename.
Published: 2026-08-19
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability permits an authenticated user to read or modify the command history of other users because the file used to store history is controlled by an external input, creating an information disclosure and potential tampering risk (CWE-73). This can reveal sensitive commands or alter audit trails, undermining trust in the storage subsystem.

Affected Systems

IBM System Storage DS8A00 models running firmware versions 10.1.3.0 through 10.11.35.0 and DS8900F models running firmware 89.40.83.0 through 89.44.25.0 are affected. The problem is addressed by updating to the listed microcode bundles such as DS8A00 bundle 10.11.34.1 or 10.12.39.0 and DS8900F bundles 89.44.17.1, 89.44.25.1, 89.44.26.0, or 89.45.10.0; note that some updates are HMC‑only while others require full code installations.

Risk and Exploitability

The CVSS base score of 5.4 indicates a medium severity attack that requires local or authenticated access; EPSS is not available and the vulnerability is not in the CISA KEV list. Attackers would need to obtain valid user credentials and exploit the file‑name control to read or write command history, so the risk is primarily to confidentiality and integrity for multi‑user environments. Given the existing access controls, it does not constitute a remote exploitation vector, but the information could be valuable for planning further attacks.

Generated by OpenCVE AI on August 20, 2026 at 10:23 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now.  Refer to https://www.ibm.com/support/pages/ds8000-code-recommendation for instructions on how to upgrade the Microcode Bundles listed below and other information. * DS8A00 fixes are delivered in Microcode Bundle 10.11.34.1 and 10.12.39.0 * Note: Customers currently on 10.11.34.0 may update to 10.11.34.1. This is an HMC-only update and does not require a full code update. * DS8900F fixes are delivered in Microcode Bundle 89.44.17.1, 89.44.25.1, 89.44.26.0 and 89.45.10.0. * Note: * Customers currently on 89.44.17.0 may update to 89.44.17.1. This is an HMC-only update and does not require a full code update. * Customers currently on 89.44.25.0 may update to 89.44.25.1. This is an HMC-only update and does not require a full code update. * 89.44.26.0 is full code update.


Vendor Workaround

DS8900F and DS8A00 commonly known as DS8K is installed in client data center and clients control access to the system. DS8K offers multiple security features like LDAP, Multi-factor authentication, audit logging etc., that allows clients to control and audit personnel access to their DS8K. In addition, DS8K has implemented IBM approved challenge-response system to control IBM service personnel accessing the system either locally or remotely. So, a malicious attacker must meticulously bypass multiple layers of authentication by exploiting known open-source vulnerabilities to gain access to DS8K. The first step would be gaining access through the client infrastructure. While the issue must be mitigated at the earliest, it doesn’t pose an immediate vulnerability due to existing access controls implemented in DS8K. In addition, DS8K supports deployment of code fixes either via remote code load process or locally by IBM personnel. DS8K clients can deploy code fixes too.


OpenCVE Recommended Actions

  • Apply the IBM‑recommended microcode bundle updates for the affected firmware version (e.g., DS8A00 10.11.34.1 or 10.12.39.0; DS8900F 89.44.17.1, 89.44.25.1, 89.44.26.0, or 89.45.10.0).
  • If a full code update is required, schedule a maintenance window to install the full bundle (e.g., DS8900F 89.44.26.0 or DS8A00 10.11.34.1).
  • If an immediate upgrade is not possible, enforce stricter access controls for command history files, limiting privileges to only those users who need to read or modify history and disabling any external control of the history filename.
  • Optionally, deploy the update via the remote code load process or local IBM personnel as described in IBM documentation, ensuring the microcode is applied correctly.

Generated by OpenCVE AI on August 20, 2026 at 10:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Ibm ds8900f Firmware
Ibm ds8a00 Firmware
CPEs cpe:2.3:h:ibm:ds8900f:-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:ds8a00:-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:ds8900f_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:ds8a00_firmware:*:*:*:*:*:*:*:*
Vendors & Products Ibm ds8900f Firmware
Ibm ds8a00 Firmware

Thu, 20 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Ibm ds8900f
Ibm ds8a00
Vendors & Products Ibm ds8900f
Ibm ds8a00

Wed, 19 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Description IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an authenticated user to read or modify another user's command history due to an externally controlled filename.
Title DS8900F and DS8A00 Information Disclosure
First Time appeared Ibm
Ibm system Storage Ds8900f
Ibm system Storage Ds8a00
Weaknesses CWE-73
CPEs cpe:2.3:o:ibm:system_storage_ds8900f:89.40.83.0:*:*:*:*:*:*:*
cpe:2.3:o:ibm:system_storage_ds8900f:89.44.25.0:*:*:*:*:*:*:*
cpe:2.3:o:ibm:system_storage_ds8A00:10.1.3.0:*:*:*:*:*:*:*
cpe:2.3:o:ibm:system_storage_ds8A00:10.11.35.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm system Storage Ds8900f
Ibm system Storage Ds8a00
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Ibm Ds8900f Ds8900f Firmware Ds8a00 Ds8a00 Firmware System Storage Ds8900f System Storage Ds8a00
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-20T16:27:36.957Z

Reserved: 2025-04-15T21:16:59.139Z

Link: CVE-2025-36398

cve-icon Vulnrichment

Updated: 2026-08-20T16:24:31.166Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T22:16:36.640

Modified: 2026-08-24T19:27:38.030

Link: CVE-2025-36398

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T10:30:03Z

Weaknesses
  • CWE-73

    External Control of File Name or Path