Unrated severityNVD Advisory· Published Aug 15, 2025· Updated Aug 15, 2025
IBM TS4500 cross-site scripting
CVE-2025-36088
Description
IBM TS4500 1.11.0.0-D00, 1.11.0.1-C00, 1.11.0.2-C00, and 1.10.00-F00 web GUI is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Affected products
2- IBM/Storage TS4500 Libraryv5cpe:2.3:h:ibm:ts4500:-:*:*:*:*:*:*:*Range: 1.11.0.0-D00
- Range: 1.10.00-F00, 1.11.0.0-D00, 1.11.0.1-C00, 1.11.0.2-C00
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.ibm.com/support/pages/node/7242263mitrevendor-advisorypatch
News mentions
0No linked articles in our index yet.