CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2025-36239: storage ts4500 library firmware 1.11.0.0, 2.11.0.0; +2 more affected products

CVE-2025-36239. CVSS 3.1 base score 6.1 (MEDIUM, Vendor/CNA). EPSS 0.00212 (percentile 0.10512), scored 2026-10-08.

Affected technology

storage ts4500 library firmware · 1.11.0.0
ibm

storage ts4500 library firmware · 2.11.0.0
ibm

diamondback tape library firmware · 1.11.0.0
ibm

diamondback tape library firmware · 2.11.0.0
ibm

Storage TS4500 Library · 1.11.0.0, 2.11.0.0
IBM

Description’s affected range: 1.11.0.0 and 2.11.0.0

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

An unauthenticated attacker can embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. Vendor/CNA’s CVSS 3.1 assessment (base score 6.1/10) rates confidentiality and integrity impact as low; availability impact as none.

Published

CWE
CWE-79
CCR priority
24.5 /100 (P4)
CVSS 3.1
6.1 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N · Vendor/CNA
EPSS
0.00212 · percentile 0.10512 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2025-36239.html