CVE-2025-36238: IBM Powervm Hypervisor

Medium severity, CVSS 6.0. EPSS: 0.2% chance of exploitation in the next 30 days.

IBM PowerVM Hypervisor FW1110.00 through FW1110.03, FW1060.00 through FW1060.51, and FW950.00 through FW950.F0 could allow a local user with administration privileges to obtain sensitive information from a Virtual TPM through a series of PowerVM service procedures.

Affected products

  • IBM Powervm Hypervisor: version fw950.00 only; version fw950.10 only; version fw950.11 only; version fw950.20 only; version fw950.30 only; version fw950.40 only; …

Published 2026-02-02. Last modified 2026-06-17.