CVE-2025-36088 Details
Description
IBM TS4500 1.11.0.0-D00, 1.11.0.1-C00, 1.11.0.2-C00, and 1.10.00-F00 web GUI is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
A cross-site scripting vulnerability has been identified in the web GUI of IBM TS4500 and IBM Diamondback Tape Libraries. This issue affects specific versions of both products and allows authenticated users to inject arbitrary JavaScript into the Web UI. The injected script could alter functionality and potentially lead to credential disclosure within a trusted session. The vulnerability arises from insufficient input sanitization in certain dialog boxes, enabling the storage and later execution of malicious code when an affected event entry is accessed.
Users of IBM TS4500 should upgrade to Fix Pack version 1.11.0.2-C03 or later. Users of IBM Diamondback Tape Library should upgrade to Fix Pack version 2.11.0.4-C01 or later. All future releases will include the fix for this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 15, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.ibm.com/support/pages/node/7242263 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ibm storage ts4500 library firmware | 1.10.00-f00 1.11.0.0-d00 1.11.0.1-c00 1.11.0.2-c00 |
CPE
Remediation
| |
| ibm storage ts4500 library | All versions |
CPE
Remediation
| |
| ibm diamondback tape library firmware | 2.11.0.0-b00 2.11.0.1-c00 2.11.0.2-b00 2.11.0.4-c00 |
CPE
Remediation
| |
| ibm diamondback tape library | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 1, 2025 | Initial Analysis | [email protected] |
| Aug 15, 2025 | New CVE Received | [email protected] |