Notification
Risk classification
Informational
Subcategories for Informational notifications
Product Lifecycle Information
Affected Domain
All TS4500, Diamondback and TS7700 users
Abstract
TSSC - Recommended Patch Matrix 15 April 2026
- New patch release:
- Patch Name: FixOSCommandInjection.
- Versions:
- 9.4.31_FixOSCommandInjection_2026-04-06
- 9.6.15_FixOSCommandInjection_2026-04-06
- Problem Description: An OS Command Injection (CWE-78) was found on a TSSC endpoint. This patch fixes the endpoint by implementing proper input sanitization and validation for all query parameters, preventing potential command injection and unauthorized operations.
Description
This generalized recommendation is made available to assist clients in implementing a patch installation strategy. It is a full field perspective, and as such, a customized recommendation, which takes into account specifics such as business upgrade windows, length of time since last installation, decommission plans, etc. may require assistance from local support teams. The word "must" in the notes below refers to bundles resolving specific problems for a targeted subset of TSSC - IMC and communicated via My Notifications to clients, or ECA (Engineering Change/Field Actions) Information Alerts to IBM Service colleagues.
| Code Level | Patch Matrix | Last Updated |
9.6 | April 2026 | |
| 9.4 | April 2026 |
TS7700 Recommended vtd_exec Matrix: https://www.ibm.com/support/pages/node/6416101
TSSC / IMC / TS3000 Code Update Recommendation: https://www.ibm.com/support/pages/node/6334617
TS4500 Code Update Recommendation: https://www.ibm.com/support/pages/node/697693
Historical Information
| Code Level | Patch Matrix | Last Updated |
9.5 | October 2025 | |
| 9.3 | October 2025 | |
| 9.2 | TSSC_Patch_Matrix_9_2 | October 2025 |
Recommended Action
Install patches to the TSSC as applicable, preferably leveraging Remote Code Load https://tape.ibmrcl.enterpriseappointments.com/v2/
Date first published
21 November 2025
Was this topic helpful?
Document Information
Modified date:
17 April 2026
UID
ibm17249182