CVE-2025-1351

IBM Storage Virtualize privilege escalation

Description

IBM Storage Virtualize 8.5, 8.6, and 8.7 products could allow a user to escalate their privileges to that of another user logging in at the same time due to a race condition in the login function.

Remediation

Solution:

  • IBM recommends that you fix this vulnerability by upgrading affected versions of IBM SAN Volume Controller, IBM Storwize V7000, IBM Storwize V5000, V5100 and V5000E, IBM FlashSystem 5000, 5100, 5200 and 5300, IBM FlashSystem 7200 and 7300, IBM FlashSystem 9100, 9200 and 9500 and IBM Storage Virtualize for Public Cloud to the code levels in the following table or higher using the download links for each product below the table. Affected Version(s) Fixed Version 8.5.0.0-8.5.0.14 8.5.0.15 8.5.1.0, 8.5.2.0-8.5.2.3, 8.5.3.0-8.5.3.1, 8.5.4.0 8.6.0.8 8.6.0.0-8.6.0.7 8.6.0.8 8.6.1.0, 8.6.2.0-8.6.2.1, 8.6.3.0 8.7.0.5 8.7.0.0-8.7.0.4 8.7.0.5 8.7.1.0, 8.7.2.0-8.7.2.1 8.7.3.0-8.7.3.1 8.7.3.2

Category

6.7
CVSS
Severity: Medium
CVSS 3.1 •
EPSS 0.01%
Vendor Advisory ibm.com
Affected: IBM Storage Virtualize
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2025-1351?
CVE-2025-1351 has been scored as a medium severity vulnerability.
How to fix CVE-2025-1351?
To fix CVE-2025-1351: IBM recommends that you fix this vulnerability by upgrading affected versions of IBM SAN Volume Controller, IBM Storwize V7000, IBM Storwize V5000, V5100 and V5000E, IBM FlashSystem 5000, 5100, 5200 and 5300, IBM FlashSystem 7200 and 7300, IBM FlashSystem 9100, 9200 and 9500 and IBM Storage Virtualize for Public Cloud to the code levels in the following table or higher using the download links for each product below the table. Affected Version(s) Fixed Version 8.5.0.0-8.5.0.14 8.5.0.15 8.5.1.0, 8.5.2.0-8.5.2.3, 8.5.3.0-8.5.3.1, 8.5.4.0 8.6.0.8 8.6.0.0-8.6.0.7 8.6.0.8 8.6.1.0, 8.6.2.0-8.6.2.1, 8.6.3.0 8.7.0.5 8.7.0.0-8.7.0.4 8.7.0.5 8.7.1.0, 8.7.2.0-8.7.2.1 8.7.3.0-8.7.3.1 8.7.3.2
Is CVE-2025-1351 being actively exploited in the wild?
As for now, there are no information to confirm that CVE-2025-1351 is being actively exploited. According to its EPSS score, there is a ~0% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2025-1351?
CVE-2025-1351 affects IBM Storage Virtualize.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.