CVE-2025-36088 Information
Aug 16, 2025
cve
Description
IBM TS4500 1.11.0.0-D00 1.11.0.1-C00 1.11.0.2-C00 and 1.10.00-F00 web GUI is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Reference
https://www.ibm.com/support/pages/node/7242263
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
5.4
Related CNNVD
CNNVD-202508-1876 (Published: 2025-08-15)
Share on: