CVE-2025-36192: Missing Authorization with the DS8900F and DS8A00 Hardware Management Console
IBM DS8A00( R10.1) 10.10.106.0 and IBM DS8A00 ( R10.0) 10.1.3.010.2.45.0 and IBM DS8900F ( R9.4) 89.40.83.089.42.18.089.44.5.0 IBM System Storage DS8000 could allow a local user with authorized CCW update permissions to delete or corrupt backups due to missing authorization in IBM Safeguarded Copy / GDPS Logical corruption protection mechanisms.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM DS8900F microcode (Microcode Bundle)to a version that resolves this vulnerability.Fixed in 89.44.17.0 - Upgrade
Upgrade
IBM DS8A00 microcode (Microcode Bundle)to a version that resolves this vulnerability.Fixed in 10.11.30.0 - Upgrade
Upgrade
IBM DS8A00 microcode (Microcode Bundle)to a version that resolves this vulnerability.Fixed in 10.11.30.0 R10.1.1 - Upgrade
Upgrade
ICS CVE_4Q2025_v1.0.isoto a version that resolves this vulnerability.Patch CVE-2024-52533 - Upgrade
Upgrade
ICS CVE_4Q2025_v1.0.isoto a version that resolves this vulnerability.Patch CVE-2025-49796 - Upgrade
Upgrade
ICS CVE_4Q2025_v1.0.isoto a version that resolves this vulnerability.Patch CVE-2025-49794 - Upgrade
Upgrade
ICS CVE_4Q2025_v1.1.isoto a version that resolves this vulnerability.Patch CVE-2025-23048 - Compensating control
For DS8900F: do not use/install the listed ICS(es) if the system has LIC bundle below R9.4; the note states the ICS(es) are not supported for DS8900F with LIC bundle below R9.4.
- Operational
Schedule Remote Code Load (RCL) via IBM Support RCL and request application of ICS/microcode bundles: for DS8900F request that 89.44.17.0 be applied; for DS8A00 request that 10.11.30.0 be applied.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36192?
CVE-2025-36192 has a medium severity due to the potential for local users to delete or corrupt critical backups.
How do I fix CVE-2025-36192?
To fix CVE-2025-36192, update your IBM DS8A00 and DS8900F systems to the latest available firmware that addresses this issue.
Which IBM products are affected by CVE-2025-36192?
CVE-2025-36192 affects IBM DS8A00 versions R10.1 and R10.0, and IBM DS8900F version R9.4.
What type of users are impacted by CVE-2025-36192?
Local users with authorized CCW update permissions can exploit CVE-2025-36192 to delete or corrupt backups.
What are the consequences of CVE-2025-36192?
The consequences of CVE-2025-36192 include possible data loss due to unauthorized backup deletion or corruption.