Stored Cross-Site Scripting Vulnerability in IBM watsonx.data Intelligence
CVE-2025-36320

6.4MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
30 June 2026

What is CVE-2025-36320?

IBM watsonx.data intelligence versions 5.2.0, 5.2.1, 5.2.2, and 5.3.0 are susceptible to a stored cross-site scripting (XSS) vulnerability. This issue permits an authenticated user to inject arbitrary JavaScript code into the Web UI. If exploited, this could compromise the integrity of the application by altering its functionality and potentially leading to the disclosure of user credentials during a trusted session.

Affected Version(s)

watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.