Executive brief
The IBM TS4500 CLI tool, used for managing high-density tape storage libraries, fails to properly validate security certificates when establishing encrypted connections. This flaw could allow a sophisticated attacker to intercept communications between the management tool and the storage system. If exploited, an attacker could steal sensitive administrative credentials or other confidential data transmitted over the network.
Technical details
The IBM TS4500 CLI tool suffers from an improper certificate validation vulnerability (CWE-295). The application fails to verify the authenticity of TLS certificates presented by the server during secure handshakes. An attacker positioned on the network path (Man-in-the-Middle) could present a self-signed or otherwise invalid certificate to intercept and decrypt traffic. While the attack requires a specific network position (High Attack Complexity), it requires no authentication or user interaction. The vulnerability is addressed in fix pack version 1.12.0.2.
Affected products
- IBM TS4500 CLI tool 0.1.31 - 1.12.0.0
Timeline
- 2026-07-21: disclosed: Initial publication by IBM
- 2026-07-21: patched: Fix pack 1.12.0.2 released
- 2026-07-28: advisory: NVD publication date