Sceawere
Vulnerability Detail
CVE-2025-36255UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
IBM DS8000 Improper Privilege Definition
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 2h ago
- Vendor
- IBM
- Product
- DS8A00( R10.0 - R10.1 )
- Attack Type
- CWE-267 Privilege Defined With Unsafe Actions
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an authenticated user to create a user with privileged user roles due to improper privileged defined with unsafe actions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-08-19T22:16:36.490Z",
"pubdate": "2026-08-19T22:16:36.490Z",
"executiveSummary": "An improper privilege definition vulnerability exists within IBM System Storage DS8A00 and IBM DS8900F storage systems. The flaw stems from unsafe actions associated with user management and role assignment. Specifically, an authenticated user can leverage improper access controls to create new user accounts assigned with highly privileged user roles.\nThe impact of successful exploitation includes unauthorized privilege escalation, allowing low-privileged or standard authenticated users to acquire administrative capabilities over the affected storage infrastructure. This compromises the confidentiality, integrity, and availability of the storage management plane and stored enterprise data.\nAffected products include IBM System Storage DS8A00 versions 10.1.3.0 through 10.11.35.0 and IBM DS8900F versions 89.40.83.0 through 89.44.25.0. Exploitation requires prior authentication to the management interface, meaning an attacker must first obtain valid credentials before executing the unauthorized role-creation workflow.\nThe risk implication is severe, as it permits lateral movement and privilege escalation within the storage management hierarchy. Organizations utilizing the affected firmware versions face significant risks of unauthorized administrative access, potentially leading to destructive storage reconfiguration or data exposure.",
"technicalDetails": "The root cause of the vulnerability lies in improper privilege definition and unsafe authorization checks implemented during user creation workflows within the affected storage management microcode. The application logic fails to properly enforce the principle of least privilege, allowing standard authenticated users to execute actions that should be strictly restricted to pre-existing administrative roles.\nThe vulnerable component handles user provisioning and access control list (ACL) assignments within the storage system's management interface. Affected versions include IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0.\nExploitation requires authentication, meaning the attacker must possess valid credentials for a baseline or low-privileged user account on the target storage system. Network exposure typically involves access to the system's management network or administrative console interfaces.\nThe attack flow proceeds as follows: First, the authenticated user initiates a request to the user provisioning module within the management interface. Due to the absence of robust authorization validation, the backend application processes the request without verifying whether the session initiator holds sufficient administrative privileges. The attacker submits parameters specifying the creation of a new user account mapped to privileged user roles. The system accepts the parameters, commits the configuration changes to the user database, and grants the newly created or modified account elevated administrative rights.\nPost-exploitation impact includes complete administrative control over the storage system management plane. An attacker wielding privileged user roles can manipulate storage volumes, modify system configurations, intercept or delete sensitive data, and potentially disrupt critical enterprise operations supported by the DS8A00 or DS8900F platforms."
}