Metrics
Affected Vendors & Products
Solution
IBM strongly recommends addressing the vulnerability now by visiting https://tape.ibmrcl.enterpriseappointments.com/v2/ or contacting IBM Service at 1-800-IBM-SERV to arrange an upgrade to the latest microcode version followed by the installation of the appropriate VTD_EXEC as needed. Minimum microcode versions are shown below: Machine Type Model Release Fix 3957 VED R5.4 Upgrade to 8.54.2.17 + VTD_EXEC.904 - OR - Upgrade to 8.54.1.27 + VTD_EXEC.904 R6.0 Upgrade to 8.60.0.115 + VTD_EXEC.905 3948 VED R5.4 Upgrade to 8.54.2.17 + VTD_EXEC.904 - OR - Upgrade to 8.54.1.27 + VTD_EXEC.904 R6.0 Upgrade to 8.60.0.115 + VTD_EXEC.905 3948 VEF R6.0 Upgrade to 8.60.0.115 + VTD_EXEC.905 The minimum VTD_EXEC version is shown below: VTD_EXEC Package Version VTD_EXEC.904 v1.27 VTD_EXEC.905 v1.11 Installation Details Concurrent Yes Local Machine State Online/Offline/Service Remote Machine State Online/Offline/Service Time of Installation Anytime Installation Time Required (mins) 60
Workaround
No workaround given by the vendor.
Link | Providers |
---|---|
https://www.ibm.com/support/pages/node/7238555 |
![]() ![]() |
Tue, 30 Sep 2025 20:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Ibm 3948-ved
Ibm 3948-ved Firmware Ibm 3948-vef Ibm 3948-vef Firmware Ibm 3957-ved Ibm 3957-ved Firmware |
|
CPEs | cpe:2.3:h:ibm:3948-ved:-:*:*:*:*:*:*:* cpe:2.3:h:ibm:3948-vef:-:*:*:*:*:*:*:* cpe:2.3:h:ibm:3957-ved:-:*:*:*:*:*:*:* cpe:2.3:o:ibm:3948-ved_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ibm:3948-vef_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ibm:3957-ved_firmware:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Ibm 3948-ved
Ibm 3948-ved Firmware Ibm 3948-vef Ibm 3948-vef Firmware Ibm 3957-ved Ibm 3957-ved Firmware |
Tue, 01 Jul 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 01 Jul 2025 01:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | IBM System Storage Virtualization Engine TS7700 3957 VED R5.4 8.54.2.17, R6.0 8.60.0.115, 3948 VED R5.4 8.54.2.17, R6.0 8.60.0.115, and 3948 VEF R6.0 8.60.0.115 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
Title | IBM System Storage Virtualization Engine TS7700 cross-site scripting | |
First Time appeared |
Ibm
Ibm system Storage Virtualization Engine Ts7700 |
|
Weaknesses | CWE-79 | |
CPEs | cpe:2.3:h:ibm:system_storage_virtualization_engine_ts7700:3948-VED:*:*:*:*:*:*:* cpe:2.3:h:ibm:system_storage_virtualization_engine_ts7700:3948-VEF:*:*:*:*:*:*:* cpe:2.3:h:ibm:system_storage_virtualization_engine_ts7700:3957-VED:*:*:*:*:*:*:* |
|
Vendors & Products |
Ibm
Ibm system Storage Virtualization Engine Ts7700 |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-08-24T11:34:14.462Z
Reserved: 2025-04-15T21:16:11.325Z
Link: CVE-2025-36056

Updated: 2025-07-01T13:37:13.666Z

Status : Analyzed
Published: 2025-07-01T01:15:28.113
Modified: 2025-09-30T20:31:22.497
Link: CVE-2025-36056

No data.

No data.