Missing Authorization with the DS8900F and DS8A00 Hardware Management Console
Missing Authorization with the DS8900F and DS8A00 Hardware Management Console
Exploit-prediction scores from FIRST. Independent scoring and analysis status from the NVD. Vendor severity from Red Hat. Exploitation assessment and catalog membership from CISA.
DS8A00 fixes are delivered in Microcode Bundle 10.11.30.0 R10.1.1 DS8900F fixes are delivered in Microcode Bundle 89.44.17.0 R9.4 SP4.2 DS8A00 customers should either schedule Remote Code Load (RCL) via https://www.ibm.com/support/pages/ibm-remote-code-load or contact IBM support, and request that 10.11.30.0 be applied to their systems.DS8900F customers should either schedule Remote Code Load (RCL) via https://www.ibm.com/support/pages/ibm-remote-code-load or contact IBM support, and request that 89.44.17.0 be applied to their systems. ICS Installation Guidelines: The ICS(es) listed below remediate critical severity vulnerabilities a) ICS CVE_4Q2025_v1.0.iso includes remediation for CVE-2024-52533 , CVE-2025-49796 , CVE-2025-49794 and is available for DS8900F and DS8A00. b) ICS CVE_4Q2025_v1.1.iso includes remediation for CVE-2025-23048 and is available for DS8900F and DS8A00. DS8900Fsystem with R9.4 LIC bundle but below 89.44.17.0 or DS8A00 with R10.0 LIC bundle but below 10.11.30.0 are recommended to install both of the above mentioned ICS(es). Customers should should either contact Remote Code Load (RCL) via https://www.ibm.com/support/pages/ibm-remote-code-load or contact IBM support to load the above mentioned ICS(es). Note: The above ICS(es) are not supported for DS8900F with LIC bundle below R9.4. Customers should either contact Remote Code Load (RCL) via https://www.ibm.com/support/pages/ibm-remote-code-load or contact IBM support to load the recommended or