Executive brief
IBM TS4300 Tape Library is a data storage appliance used in enterprise environments to manage backup and archival data. The vulnerability allows authenticated users to flood the email system with excessive requests, causing denial of service to email notifications and potentially overwhelming mail servers. This could disrupt critical alerting and operational notifications for storage management teams.
Technical details
The vulnerability is an improper control of interaction frequency (CWE-799) in the email-related functions of the web GUI and APIs. Authenticated users can repeatedly invoke email-sending requests without rate limiting, generating excessive email traffic that consumes mail server resources and causes denial of service. The attack requires valid authentication credentials and network access to the TS4300 web interface or APIs. IBM has resolved this issue by implementing rate limiting and request-throttling controls for email operations. Versions 1.1.0.1 through 1.7.1.1 are affected; users should upgrade to version 1.7.2.0 or later.
Affected products
- IBM TS4300 Tape Library 1.1.0.1 through 1.7.1.1
Timeline
- 2026-09-11: disclosed: Initial publication of security bulletin
- 2026-09-11: patched: Fix available in version 1.7.2.0 and later