Cross-Site Scripting in IBM TS4500 Web GUI
CVE-2025-36088

5.4MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
15 August 2025

What is CVE-2025-36088?

The IBM TS4500 web GUI versions 1.10.00-F00 and 1.11.0.0-D00 through 1.11.0.2-C00 are susceptible to a cross-site scripting vulnerability. This issue allows an authenticated user to inject arbitrary JavaScript code into the web interface. The consequence is a potential alteration of the intended functionality, which could result in unauthorized access to user credentials during a trusted session. Users are encouraged to apply available patches to mitigate this risk.

Affected Version(s)

Storage TS4500 Library 1.11.0.0-D00

Storage TS4500 Library 1.11.0.1-C00

Storage TS4500 Library 1.11.0.2-C00

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Florian Holley
.
CVE-2025-36088 : Cross-Site Scripting in IBM TS4500 Web GUI