Description
IBM Total Storage Service Console (TSSC) / TS4500 IMC 9.2, 9.3, 9.4, 9.5, 9.6 TSSC/IMC could allow an unauthenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input.
Published: 2026-04-22
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Affected Product(s)Version(s)Remediation/Fix/InstructionsTotal Storage Service Console (TSSC) / TS4500 IMC9.4.14, 9.4.21, 9.4.26, 9.6.10, 9.5.8,Upgrade to 9.4.31/9.6.15 Download patch 9.X.X_FixOSCommandInjection_2026-04-06 or 9.X.X_FixOSCommandInjection_2026-04-06 and execute on TSSC/IMC system. Please see instructions below. Total Storage Service Console (TSSC) / TS4500 IMC9.4.31,  9.6.15Download patch 9.X.X_FixOSCommandInjection_2026-04-06 or 9.X.X_FixOSCommandInjection_2026-04-06 and execute on TSSC/IMC system. Please see instructions below. For information on how to download the patch please refer to the following page:  Available Updates https://www.ibm.com/docs/en/tssc

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 00:00:00 +0000

Type Values Removed Values Added
Description IBM Total Storage Service Console (TSSC) / TS4500 IMC 9.2, 9.3, 9.4, 9.5, 9.6 TSSC/IMC could allow an unauthenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input.
Title TSSC/IMC is vulnerable to OS Command Injection
First Time appeared Ibm
Ibm total Storage Service Console Tssc Ts4500 Imc
Weaknesses CWE-78
CPEs cpe:2.3:a:ibm:total_storage_service_console_tssc__ts4500_imc:9.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:total_storage_service_console_tssc__ts4500_imc:9.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm total Storage Service Console Tssc Ts4500 Imc
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Ibm Total Storage Service Console Tssc Ts4500 Imc
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-04-23T13:57:14.969Z

Reserved: 2026-04-09T00:42:21.168Z

Link: CVE-2026-5935

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-04-23T00:16:46.900

Modified: 2026-04-23T00:16:46.900

Link: CVE-2026-5935

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses