Vulnerability Details CVE-2025-36239
IBM Storage TS4500 Library 1.11.0.0 and 2.11.0.0
is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 27.6%
CVSS Severity
CVSS v3 Score 6.1
Products affected by CVE-2025-36239
-
cpe:2.3:h:ibm:diamondback_tape_library:-
-
cpe:2.3:h:ibm:storage_ts4500_library:-
-
cpe:2.3:o:ibm:diamondback_tape_library_firmware:1.11.0.0
-
cpe:2.3:o:ibm:diamondback_tape_library_firmware:2.11.0.0
-
cpe:2.3:o:ibm:storage_ts4500_library_firmware:1.11.0.0
-
cpe:2.3:o:ibm:storage_ts4500_library_firmware:2.11.0.0