IBM Storage TS4500 Library 1.11.0.0 and 2.11.0.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

Project Subscriptions

Vendors Products
Diamondback Tape Library Subscribe
Diamondback Tape Library Firmware Subscribe
Storage Ts4500 Library Subscribe
Storage Ts4500 Library Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2024-55025 IBM Storage TS4500 Library 1.11.0.0 and 2.11.0.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
Fixes

Solution

For the 1.11.0.0 release, upgrade to version 1.12.0.0-C00 or later, available from IBM Fix Central http://www-933.ibm.com/support/fixcentral/ .   For the 2.11.0.0 release, upgrade to version 2.12.0.0-C00 or later, available from IBM Fix Central http://www-933.ibm.com/support/fixcentral/ . All future releases will include the fix for this vulnerability.


Workaround

No workaround given by the vendor.

History

Thu, 11 Dec 2025 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Ibm diamondback Tape Library
Ibm diamondback Tape Library Firmware
Ibm storage Ts4500 Library
Ibm storage Ts4500 Library Firmware
CPEs cpe:2.3:h:ibm:diamondback_tape_library:-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:storage_ts4500_library:-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:diamondback_tape_library_firmware:1.11.0.0:*:*:*:*:*:*:*
cpe:2.3:o:ibm:diamondback_tape_library_firmware:2.11.0.0:*:*:*:*:*:*:*
cpe:2.3:o:ibm:storage_ts4500_library_firmware:1.11.0.0:*:*:*:*:*:*:*
cpe:2.3:o:ibm:storage_ts4500_library_firmware:2.11.0.0:*:*:*:*:*:*:*
Vendors & Products Ibm diamondback Tape Library
Ibm diamondback Tape Library Firmware
Ibm storage Ts4500 Library
Ibm storage Ts4500 Library Firmware

Mon, 29 Sep 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 27 Sep 2025 02:00:00 +0000

Type Values Removed Values Added
Description IBM Storage TS4500 Library 1.11.0.0 and 2.11.0.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
Title IBM Storage TS4500 Library cross-site request forgery
First Time appeared Ibm
Ibm ts4500
Weaknesses CWE-352
CPEs cpe:2.3:h:ibm:ts4500:-:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm ts4500
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2025-09-29T14:02:12.320Z

Reserved: 2024-08-07T13:29:48.160Z

Link: CVE-2024-43192

cve-icon Vulnrichment

Updated: 2025-09-29T14:02:04.014Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-27T02:15:31.140

Modified: 2025-12-11T22:10:37.530

Link: CVE-2024-43192

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses