IBM Storage TS4500 Library 1.11.0.0 and 2.11.0.0

is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

Project Subscriptions

Vendors Products
Diamondback Tape Library Subscribe
Diamondback Tape Library Firmware Subscribe
Storage Ts4500 Library Subscribe
Storage Ts4500 Library Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2025-31399 IBM Storage TS4500 Library 1.11.0.0 and 2.11.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Fixes

Solution

For the 1.11.0.0 release, upgrade to version 1.12.0.0-C00 or later, available from IBM Fix Central http://www-933.ibm.com/support/fixcentral/ .   For the 2.11.0.0 release, upgrade to version 2.12.0.0-C00 or later, available from IBM Fix Central http://www-933.ibm.com/support/fixcentral/ . All future releases will include the fix for this vulnerability.


Workaround

No workaround given by the vendor.

History

Thu, 11 Dec 2025 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Ibm diamondback Tape Library
Ibm diamondback Tape Library Firmware
Ibm storage Ts4500 Library
Ibm storage Ts4500 Library Firmware
CPEs cpe:2.3:h:ibm:diamondback_tape_library:-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:storage_ts4500_library:-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:diamondback_tape_library_firmware:1.11.0.0:*:*:*:*:*:*:*
cpe:2.3:o:ibm:diamondback_tape_library_firmware:2.11.0.0:*:*:*:*:*:*:*
cpe:2.3:o:ibm:storage_ts4500_library_firmware:1.11.0.0:*:*:*:*:*:*:*
cpe:2.3:o:ibm:storage_ts4500_library_firmware:2.11.0.0:*:*:*:*:*:*:*
Vendors & Products Ibm diamondback Tape Library
Ibm diamondback Tape Library Firmware
Ibm storage Ts4500 Library
Ibm storage Ts4500 Library Firmware

Mon, 29 Sep 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 27 Sep 2025 02:00:00 +0000

Type Values Removed Values Added
Description IBM Storage TS4500 Library 1.11.0.0 and 2.11.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Title IBM Storage TS4500 Library cross-site scripting
First Time appeared Ibm
Ibm ts4500
Weaknesses CWE-79
CPEs cpe:2.3:h:ibm:ts4500:-:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm ts4500
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2025-09-29T13:59:37.166Z

Reserved: 2025-04-15T21:16:42.825Z

Link: CVE-2025-36239

cve-icon Vulnrichment

Updated: 2025-09-29T13:59:13.769Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-27T02:15:32.197

Modified: 2025-12-11T22:09:47.937

Link: CVE-2025-36239

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses