IBM TS4500 1.11.0.0-D00, 1.11.0.1-C00, 1.11.0.2-C00, and 1.10.00-F00 web GUI is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

Project Subscriptions

Vendors Products
Diamondback Tape Library Subscribe
Diamondback Tape Library Firmware Subscribe
Storage Ts4500 Library Subscribe
Storage Ts4500 Library Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2025-25048 IBM TS4500 1.11.0.0-D00, 1.11.0.1-C00, 1.11.0.2-C00, and 1.10.00-F00 web GUI is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Fixes

Solution

For the 1.11.0 release, upgrade to Fix Pack version 1.11.0.2-C03 or later. For the 2.11.0 release, upgrade to Fix Pack version 2.11.0.4-C01 or later.


Workaround

No workaround given by the vendor.

History

Mon, 01 Dec 2025 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Ibm diamondback Tape Library
Ibm diamondback Tape Library Firmware
Ibm storage Ts4500 Library
Ibm storage Ts4500 Library Firmware
CPEs cpe:2.3:h:ibm:diamondback_tape_library:-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:storage_ts4500_library:-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:diamondback_tape_library_firmware:2.11.0.0-b00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:diamondback_tape_library_firmware:2.11.0.1-c00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:diamondback_tape_library_firmware:2.11.0.2-b00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:diamondback_tape_library_firmware:2.11.0.4-c00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:storage_ts4500_library_firmware:1.10.00-f00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:storage_ts4500_library_firmware:1.11.0.0-d00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:storage_ts4500_library_firmware:1.11.0.1-c00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:storage_ts4500_library_firmware:1.11.0.2-c00:*:*:*:*:*:*:*
Vendors & Products Ibm diamondback Tape Library
Ibm diamondback Tape Library Firmware
Ibm storage Ts4500 Library
Ibm storage Ts4500 Library Firmware

Fri, 15 Aug 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 15 Aug 2025 19:30:00 +0000

Type Values Removed Values Added
Description IBM TS4500 1.11.0.0-D00, 1.11.0.1-C00, 1.11.0.2-C00, and 1.10.00-F00 web GUI is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Title IBM TS4500 cross-site scripting
First Time appeared Ibm
Ibm ts4500
Weaknesses CWE-79
CPEs cpe:2.3:h:ibm:ts4500:-:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm ts4500
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2025-08-15T19:48:45.853Z

Reserved: 2025-04-15T21:16:13.891Z

Link: CVE-2025-36088

cve-icon Vulnrichment

Updated: 2025-08-15T19:48:41.101Z

cve-icon NVD

Status : Analyzed

Published: 2025-08-15T20:15:27.563

Modified: 2025-12-01T18:06:38.430

Link: CVE-2025-36088

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses