IBM Storage TS4500 and Diamondback Tape Libraries Cross-Site Request Forgery Vulnerability

Vulnerability

A cross-site request forgery (CSRF) vulnerability has been identified in IBM Storage TS4500 Library versions 1.11.0.0 and 2.11.0.0, as well as in all versions of IBM Diamondback Tape Library. This vulnerability allows attackers to perform malicious and unauthorized actions by exploiting the trust that the application has in authenticated users.

Impact

Exploitation of this vulnerability could lead to unauthorized actions being performed on behalf of an authenticated user, potentially allowing attackers to manipulate data or application state in ways that are not intended or authorized.

Remediation

Users of IBM Storage TS4500 Library 1.11.0.0 should upgrade to version 1.12.0.0-C00 or later. Users of IBM Storage TS4500 Library 2.11.0.0 should upgrade to version 2.12.0.0-C00 or later. Both versions are available from IBM Fix Central. All future releases will include the fix for this vulnerability.

Added: Sep 27, 2025, 2:18 AM
Updated: Sep 27, 2025, 2:18 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
6.4
remediation
7.7
relevance
0.6
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.