CVE-2025-36035
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
14/09/2025
Last modified:
19/12/2025
Description
IBM PowerVM Hypervisor FW950.00 through FW950.E0, FW1050.00 through FW1050.50, and FW1060.00 through FW1060.40 could allow a local privileged user to cause a denial of service by issuing a specially crafted IBM i hypervisor call that would disclose memory contents or consume excessive memory resources.
Impact
Base Score 3.x
6.70
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:ibm:powervm_hypervisor:*:*:*:*:*:*:*:* | FW950.00 (including) | FW950.E0 (including) |
| cpe:2.3:h:ibm:power_system_e950_\(9040-mr9\):-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:ibm:power_system_e980_\(9080-m9s\):-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:ibm:power_system_h922_\(9223-22h\):-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:ibm:power_system_h922_\(9223-22s\):-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:ibm:power_system_h924_\(\(9223-42s\):-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:ibm:power_system_h924_\(9223-42h\):-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:ibm:power_system_l922_\(9008-22l\):-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:ibm:power_system_s914_\(9009-41a\):-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:ibm:power_system_s914_\(9009-41g\):-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:ibm:power_system_s922_\(9009-22a\):-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:ibm:power_system_s922_\(9009-22g\):-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:ibm:power_system_s924_\(9009-42a\):-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:ibm:power_system_s924_\(9009-42g\):-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:ibm:powervm_hypervisor:*:*:*:*:*:*:*:* | FW1050.00 (including) | FW1050.50 (including) |
To consult the complete list of CPE names with products and versions, see this page



