Stored Cross-Site Scripting Vulnerability in IBM watsonx.data Intelligence
CVE-2025-36320
6.4MEDIUM
What is CVE-2025-36320?
IBM watsonx.data intelligence versions 5.2.0, 5.2.1, 5.2.2, and 5.3.0 are susceptible to a stored cross-site scripting (XSS) vulnerability. This issue permits an authenticated user to inject arbitrary JavaScript code into the Web UI. If exploited, this could compromise the integrity of the application by altering its functionality and potentially leading to the disclosure of user credentials during a trusted session.
Affected Version(s)
watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0