IBM System Storage Virtualization Engine TS7700 3957 VED R5.4 8.54.2.17, R6.0 8.60.0.115, 3948 VED R5.4 8.54.2.17, R6.0 8.60.0.115, and 3948 VEF R6.0 8.60.0.115 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
History

Tue, 01 Jul 2025 01:15:00 +0000

Type Values Removed Values Added
Description IBM System Storage Virtualization Engine TS7700 3957 VED R5.4 8.54.2.17, R6.0 8.60.0.115, 3948 VED R5.4 8.54.2.17, R6.0 8.60.0.115, and 3948 VEF R6.0 8.60.0.115 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Title IBM System Storage Virtualization Engine TS7700 cross-site scripting
First Time appeared Ibm
Ibm system Storage Virtualization Engine Ts7700
Weaknesses CWE-79
CPEs cpe:2.3:h:ibm:system_storage_virtualization_engine_ts7700:3948-VED:*:*:*:*:*:*:*
cpe:2.3:h:ibm:system_storage_virtualization_engine_ts7700:3948-VEF:*:*:*:*:*:*:*
cpe:2.3:h:ibm:system_storage_virtualization_engine_ts7700:3957-VED:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm system Storage Virtualization Engine Ts7700
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2025-07-01T01:00:03.022Z

Reserved: 2025-04-15T21:16:11.325Z

Link: CVE-2025-36056

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-07-01T01:15:28.113

Modified: 2025-07-01T01:15:28.113

Link: CVE-2025-36056

cve-icon Redhat

No data.