CVE-2025-36120: IBM Storage Virtualize

High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.

IBM Storage Virtualize 8.4, 8.5, 8.6, and 8.7 could allow an authenticated user to escalate their privileges in an SSH session due to incorrect authorization checks to access resources.

Affected products

  • IBM Storage Virtualize: from 8.4.0.0, before 8.4.0.18 (fixed in 8.4.0.18); from 8.5.0.0, before 8.5.0.16 (fixed in 8.5.0.16); from 8.5.2.0, up to and including 8.5.2.3; from 8.6.0.0, before 8.6.0.9 (fixed in 8.6.0.9); from 8.7.0.0, before 8.7.0.6 (fixed in 8.7.0.6); from 8.7.3.0, before 8.7.3.3 (fixed in 8.7.3.3); …

Published 2025-08-18. Last modified 2026-06-17.