Known vulnerabilities in System Storage DS8900F
Vendor:
IBM Corporation
Software:
System Storage DS8900F
Software CPE:
cpe:2.3:a:ibm_corporation:system_storage_ds8900f:*:*:*:*:*:*:*:*
Website:
https://www.ibm.com/us-en
Total vulnerabilities:
16
Public exploits:
1
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (16)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU109938 - Exposure of sensitive information to an unauthorized actor CVE-2025-46421 |
CWE-200 | Low | 89.44.4.0 R9.4 SP4 | 29.05.2025 |
SB2025052715 SB20250529101 SB20250529102 and 26 more |
||
| #VU109937 - Missing release of memory after effective lifetime CVE-2025-46420 |
CWE-401 | Low | 89.44.4.0 R9.4 SP4 | 29.05.2025 |
SB2025052992 SB20250529101 SB20250529102 and 29 more |
||
| #VU109936 - Use After Free CVE-2025-32911 |
CWE-416 | High | 89.44.4.0 R9.4 SP4 | 29.05.2025 |
SB2025052992 SB2025052997 SB2025052998 and 33 more |
||
| #VU109931 - Buffer over-read CVE-2025-32050 |
CWE-126 | Medium | 89.44.4.0 R9.4 SP4 | 29.05.2025 |
SB2024111329 SB2025052980 SB2025052994 and 28 more |
||
| #VU109929 - Buffer over-read CVE-2025-32052 |
CWE-126 | Medium | 89.44.4.0 R9.4 SP4 | 29.05.2025 |
SB2024111329 SB2025052980 SB2025052994 and 32 more |
||
| #VU109927 - Buffer over-read CVE-2025-32053 |
CWE-126 | Medium | 89.44.4.0 R9.4 SP4 | 29.05.2025 |
SB2024111329 SB2025052980 SB2025052994 and 29 more |
||
| #VU109838 - NULL Pointer Dereference CVE-2025-32913 |
CWE-476 | High | 89.44.4.0 R9.4 SP4 | 27.05.2025 |
SB2025052718 SB2025052723 SB2025052997 and 33 more |
||
| #VU109834 - Out-of-bounds read CVE-2025-32906 |
CWE-125 | Medium | 89.44.4.0 R9.4 SP4 | 27.05.2025 |
SB2025052715 SB2025052723 SB2025052994 and 37 more |
||
| #VU105723 - Stack-based buffer overflow CVE-2024-8176 |
CWE-121 | High | 89.44.4.0 R9.4 SP4 | 14.03.2025 |
SB2025031426 SB2025031429 SB2025031430 and 105 more |
||
| #VU105715 - Out-of-bounds write CVE-2025-27363 |
CWE-787 | Critical | 89.44.4.0 R9.4 SP4 | 14.03.2025 |
SB2025031402 SB2025031502 SB2025031750 and 97 more |
||
| #VU104099 - Use After Free CVE-2024-56171 |
CWE-416 | High | 89.44.4.0 R9.4 SP4 | 20.02.2025 |
SB2025022003 SB2025022010 SB2025022023 and 111 more |
||
| #VU104098 - Stack-based buffer overflow CVE-2025-24928 |
CWE-121 | High | 89.44.4.0 R9.4 SP4 | 20.02.2025 |
SB2025022003 SB2025022010 SB2025022023 and 111 more |
||
| #VU93519 - Out-of-bounds read CVE-2024-37371 |
CWE-125 | Medium | 89.44.4.0 R9.4 SP4 | 01.07.2024 |
SB2024070148 SB2024070491 SB2024070496 and 114 more |
||
| #VU93518 - Improper input validation CVE-2024-37370 |
CWE-20 | Medium | 89.44.4.0 R9.4 SP4 | 01.07.2024 |
SB2024070148 SB2024070491 SB2024070496 and 96 more |
||
| #VU92263 - Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') CVE-2024-22326 |
CWE-90 | Medium | 89.41.23.0 R9.4 SP1.1 | 19.06.2024 |
SB2024061956 |
||
| #VU9687 - Memory corruption CVE-2017-9047 |
CWE-119 | Low | 89.44.4.0 R9.4 SP4 | 19.12.2017 |
SB2017121308 SB2017111019 SB2022110928 and 29 more |