Executive brief
IBM Total Storage Service Console (TSSC) and TS4500 IMC, which are used to manage and service enterprise tape storage systems, contain a security vulnerability. An unauthenticated attacker could remotely execute commands on the system with standard user privileges. This could lead to unauthorized access to storage management functions or serve as a foothold for further attacks on the storage network.
Technical details
An OS command injection vulnerability (CWE-78) exists in the IBM Total Storage Service Console (TSSC) and TS4500 IMC due to improper validation of user-supplied input at HTTP/HTTPS endpoints. A remote, unauthenticated attacker can exploit this by sending specially crafted requests to the affected web interface. Successful exploitation allows the execution of arbitrary operating system commands with the privileges of a normal user. IBM has released patches (e.g., 9.X.X_FixOSCommandInjection_2026-04-06) and recommends upgrading to versions 9.4.31 or 9.6.15.
Affected products
- IBM Total Storage Service Console (TSSC) / TS4500 IMC 9.2, 9.3, 9.4, 9.5, 9.6
Timeline
- 2026-04-20: disclosed: Initial publication by IBM
- 2026-04-22: advisory: NVD publication date
- 2026-05-18: other: NVD last modified date