Cross-Site Scripting Vulnerability in IBM Watson Assistant for Cloud Pak for Data
CVE-2019-4428
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 9 December 2019
What is CVE-2019-4428?
IBM Watson Assistant for IBM Cloud Pak for Data versions 1.0.0 through 1.3.0 are exposed to a cross-site scripting vulnerability. This flaw allows attackers to inject arbitrary JavaScript into the Web UI, potentially modifying the application’s behavior. Exploitation of this vulnerability could lead to unauthorized actions and sensitive data exposure, as it could facilitate credential theft during a trusted user session. Organizations utilizing these versions must immediately assess and mitigate this risk to safeguard their operations.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Watson Assistant for IBM Cloud Pak for Data 1.0.0
Watson Assistant for IBM Cloud Pak for Data 1.3.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved