VYPR
Medium severity5.4NVD Advisory· Published Aug 15, 2025· Updated Jun 17, 2026

CVE-2025-36088

CVE-2025-36088

Description

IBM TS4500 1.11.0.0-D00, 1.11.0.1-C00, 1.11.0.2-C00, and 1.10.00-F00 web GUI is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

10
  • cpe:2.3:h:ibm:ts4500:-:*:*:*:*:*:*:*
    Range: 1.11.0.0-D00
  • cpe:2.3:o:ibm:diamondback_tape_library_firmware:2.11.0.0-b00:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:o:ibm:diamondback_tape_library_firmware:2.11.0.0-b00:*:*:*:*:*:*:*
    • cpe:2.3:o:ibm:diamondback_tape_library_firmware:2.11.0.1-c00:*:*:*:*:*:*:*
    • cpe:2.3:o:ibm:diamondback_tape_library_firmware:2.11.0.2-b00:*:*:*:*:*:*:*
    • cpe:2.3:o:ibm:diamondback_tape_library_firmware:2.11.0.4-c00:*:*:*:*:*:*:*
  • cpe:2.3:o:ibm:storage_ts4500_library_firmware:1.10.00-f00:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:o:ibm:storage_ts4500_library_firmware:1.10.00-f00:*:*:*:*:*:*:*
    • cpe:2.3:o:ibm:storage_ts4500_library_firmware:1.11.0.0-d00:*:*:*:*:*:*:*
    • cpe:2.3:o:ibm:storage_ts4500_library_firmware:1.11.0.1-c00:*:*:*:*:*:*:*
    • cpe:2.3:o:ibm:storage_ts4500_library_firmware:1.11.0.2-c00:*:*:*:*:*:*:*
  • IBM/TS4500llm-create

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.