VYPR

System Storage Virtualization Engine Ts7700

by IBM

CVEs (7)

  • CVE-2021-29908CriOct 6, 2021
    risk 0.64cvss 9.8epss 0.02

    The IBM TS7700 Management Interface is vulnerable to unauthenticated access. By accessing a specially-crafted URL, an attacker may gain administrative access to the Management Interface without authentication. IBM X-Force ID: 207747.

  • CVE-2023-24958HigMay 4, 2023
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in the IBM TS7700 Management Interface 8.51.2.12, 8.52.200.111, 8.52.102.13, and 8.53.0.63 could allow an authenticated user to submit a specially crafted URL leading to privilege escalation and remote code execution. IBM X-Force ID: 246320.

  • CVE-2025-2141MedJul 1, 2025
    risk 0.40cvss 6.1epss 0.00

    IBM System Storage Virtualization Engine TS7700 3957 VED R5.4 8.54.2.17, R6.0 8.60.0.115, 3948 VED R5.4 8.54.2.17, R6.0 8.60.0.115, and 3948 VEF R6.0 8.60.0.115 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript…

  • CVE-2025-36056MedJul 1, 2025
    risk 0.35cvss 5.4epss 0.00

    IBM System Storage Virtualization Engine TS7700 3957 VED R5.4 8.54.2.17, R6.0 8.60.0.115, 3948 VED R5.4 8.54.2.17, R6.0 8.60.0.115, and 3948 VEF R6.0 8.60.0.115 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript…

  • CVE-2023-49878MedDec 13, 2023
    risk 0.28cvss 4.3epss 0.01

    IBM System Storage Virtualization Engine TS7700 3957-VEC, 3948-VED and 3957-VEC could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the…

  • CVE-2023-49877MedDec 13, 2023
    risk 0.28cvss 4.3epss 0.01

    IBM System Storage Virtualization Engine TS7700 3957-VEC, 3948-VED and 3957-VEC could allow a remote authenticated user to obtain sensitive information, caused by improper filtering of URLs. By submitting a specially crafted HTTP GET request, an attacker could exploit this…

  • CVE-2014-3048Jun 8, 2014
    risk 0.00cvss epss 0.00

    Unspecified vulnerability on the IBM System Storage Virtualization Engine TS7700 allows local users to gain privileges by leveraging the TSSC service-user role to enter a crafted SSH command.