Executive brief
IBM System Storage DS8000 is an enterprise storage system used to store critical business data and backups. A vulnerability in the Safeguarded Copy and GDPS logical corruption protection mechanisms allows an authorized user with CCW update permissions to delete or corrupt backups without proper authorization checks, potentially leading to loss of recovery capabilities and business continuity impact.
Technical details
This vulnerability is an authorization bypass in IBM System Storage DS8000's Safeguarded Copy and GDPS Logical corruption protection mechanisms. The flaw allows a local user with authorized CCW (Control Code Word) update permissions to delete or corrupt backups due to missing authorization checks. The attack requires local access and authenticated CCW update privileges, but bypasses additional authorization controls that should protect backup integrity. Successful exploitation allows deletion or corruption of critical backup data, undermining disaster recovery and compliance capabilities. Patches are available via IBM support bulletin and firmware updates for DS8900F and DS8A00 models.
Affected products
- IBM System Storage DS8A00 R10.1 10.10.106.0, R10.0 10.1.3.010.2.45.0
- IBM System Storage DS8900F R9.4 89.40.83.0, 89.42.18.0, 89.44.5.0
Timeline
- 2025-12-26: disclosed: CVE-2025-36192 published