CVE-2025-36238: Power System Exposure of Sensitive System Information
IBM PowerVM Hypervisor could allow a local user with administration privileges to obtain sensitive information from a Virtual TPM through a series of PowerVM service procedures.
Other sources
IBM PowerVM Hypervisor FW1110.00 through FW1110.03, FW1060.00 through FW1060.51, and FW950.00 through FW950.F0 could allow a local user with administration privileges to obtain sensitive information from a Virtual TPM through a series of PowerVM service procedures.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36238?
CVE-2025-36238 is considered a medium severity vulnerability that allows local users with administrative privileges to access sensitive information.
How do I fix CVE-2025-36238?
To remediate CVE-2025-36238, update IBM PowerVM Hypervisor to the latest firmware versions recommended by IBM.
What systems are affected by CVE-2025-36238?
CVE-2025-36238 affects IBM PowerVM Hypervisor versions from FW1110.00 to FW1110.03, FW1060.00 to FW1060.51, and FW950.00 to FW950.F0.
Who is impacted by CVE-2025-36238?
Local users with administrative privileges on affected IBM PowerVM Hypervisor systems are impacted by CVE-2025-36238.
What kind of information can be exposed due to CVE-2025-36238?
CVE-2025-36238 may expose sensitive information from a Virtual TPM to authorized local users.