CVE-2025-36118: IBM Storage Virtualize Information Disclosure

Published Nov 14, 2025
·
Updated

IBM Storage Virtualize 8.4, 8.5, 8.7, and 9.1 IKEv1 implementation allows remote attackers to obtain sensitive information from device memory via a Security Association (SA) negotiation request.

Other sources

IBM Storage Virtualize IKEv1 implementation allows remote attackers to obtain sensitive information from device memory via a Security Association (SA) negotiation request.

IBM

Affected Software

9 affected components
IBM Storage Virtualize>=8.4<=9.1
IBM Storage Virtualize<=8.4
IBM Storage Virtualize<=8.5
IBM Storage Virtualize<=8.7
IBM Storage Virtualize<=9.1
IBM Storage Virtualize=8.4.0.0
IBM Storage Virtualize=8.5.0.0
IBM Storage Virtualize=8.7.0.0
IBM Storage Virtualize=9.1.0.0

Remediation

Information

Remediation/Fixes IBM recommends that you fix this vulnerability by upgrading affected versions of IBM SAN Volume Controller, IBM Storwize V7000, IBM Storwize V5000, V5100 and V5000E, IBM FlashSystem 5000, 5100, 5200 and 5300, IBM FlashSystem 7200 and 7300, IBM FlashSystem 9100, 9200 and 9500 and IBM Storage Virtualize for Public Cloud to the code levels in the following table or higher using the download links for each product below the table. Affected Version(s) Fixed Version 8.4.0.0-8.4.0.9 8.4.0.10 8.4.1.0, 8.4.2.0-8.4.2.1, 8.4.3.0-8.4.3.1 8.5.0.7 8.5.0.0-8.5.0.6 8.5.0.7 8.5.1.0 8.5.2.0, 8.6.0.0 8.7.0.0-8.7.0.7 8.7.0.8 8.7.1.0, 8.7.2.0-8.7.2.1 9.1.0.2 9.1.0.0-9.1.0.1 9.1.0.2, 9.1.1.0 Latest IBM SAN Volume Controller Code Latest IBM Storwize V7000 Code Latest IBM Storwize V5000 and V5100 Code Latest IBM Storwize V5000E Code Latest IBM FlashSystem 9500 Code Latest IBM FlashSystem 9100 Family Code Latest IBM FlashSystem 9200 Code Latest IBM FlashSystem 7300 Code Latest IBM FlashSystem 7200 Code Latest IBM FlashSystem 5000 and 5200 Code Latest IBM FlashSystem 5300 Code Latest IBM Storage Virtualize for Public Cloud

Event History

Nov 14, 2025
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Nov 17, 2025
CVE Published
via MITRE·08:47 PM
Data Sourced
via MITRE·08:47 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Frequently Asked Questions

1

What is the severity of CVE-2025-36118?

CVE-2025-36118 has been classified as a high severity vulnerability due to the potential for sensitive information disclosure.

2

How do I fix CVE-2025-36118?

To mitigate CVE-2025-36118, it is recommended to upgrade IBM Storage Virtualize to a version above 9.1.

3

Who is affected by CVE-2025-36118?

CVE-2025-36118 affects IBM Storage Virtualize versions 8.4, 8.5, 8.7, and 9.1.

4

What type of vulnerability is CVE-2025-36118?

CVE-2025-36118 is an information disclosure vulnerability related to IKEv1 implementation.

5

What can attackers do with CVE-2025-36118?

Attackers can exploit CVE-2025-36118 to obtain sensitive information from device memory through a Security Association negotiation request.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203