Vulnerability Description
IBM TS4500 1.11.0.0-D00, 1.11.0.1-C00, 1.11.0.2-C00, and 1.10.00-F00 web GUI is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Storage Ts4500 Library Firmware | 1.10.00-f00 |
| Ibm | Storage Ts4500 Library | - |
| Ibm | Diamondback Tape Library Firmware | 2.11.0.0-b00 |
| Ibm | Diamondback Tape Library | - |
Related Weaknesses (CWE)
References
- https://www.ibm.com/support/pages/node/7242263Vendor Advisory
FAQ
What is CVE-2025-36088?
CVE-2025-36088 is a vulnerability with a CVSS score of 5.4 (MEDIUM). IBM TS4500 1.11.0.0-D00, 1.11.0.1-C00, 1.11.0.2-C00, and 1.10.00-F00 web GUI is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code i...
How severe is CVE-2025-36088?
CVE-2025-36088 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-36088?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Storage Ts4500 Library Firmware, Ibm Storage Ts4500 Library, Ibm Diamondback Tape Library Firmware, Ibm Diamondback Tape Library.