CVE-2025-36120: IBM Storage Virtualize privilege escalation
IBM Storage Virtualize 8.4, 8.5, 8.6, and 8.7 could allow an authenticated user to escalate their privileges in an SSH session due to incorrect authorization checks to access resources.
Other sources
IBM Storage Virtualize could allow an authenticated user to escalate their privileges in an SSH session due to incorrect authorization checks to access resources.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36120?
CVE-2025-36120 has a critical severity level due to its potential for privilege escalation.
How do I fix CVE-2025-36120?
To fix CVE-2025-36120, you should update IBM Storage Virtualize to the latest patched version as recommended by IBM.
Who is affected by CVE-2025-36120?
CVE-2025-36120 affects users of IBM Storage Virtualize versions 8.4 through 8.7.
What types of attacks can CVE-2025-36120 enable?
CVE-2025-36120 can enable authenticated users to escalate their privileges in an SSH session.
Is CVE-2025-36120 remotely exploitable?
CVE-2025-36120 is not remotely exploitable as it requires valid authentication to exploit.