CVE-2024-49790: IBM Watson Studio on Cloud Pak for Data cross-site scripting
IBM Watson Studio on Cloud Pak for Data 4.0 and 5.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM Watson Studio on Cloud Pak for Data is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-49790?
CVE-2024-49790 is classified as a medium severity cross-site scripting vulnerability.
How do I fix CVE-2024-49790?
To fix CVE-2024-49790, ensure you update IBM Watson Studio on Cloud Pak for Data to the latest security patch provided by IBM.
Which versions of IBM Watson Studio on Cloud Pak for Data are affected by CVE-2024-49790?
CVE-2024-49790 affects IBM Watson Studio on Cloud Pak for Data versions 4.0 and 5.0.
What are the risks associated with CVE-2024-49790?
The risks of CVE-2024-49790 include potential unauthorized execution of JavaScript code, which can lead to credential disclosure and other security issues.
Who should be concerned about CVE-2024-49790?
Organizations using IBM Watson Studio on Cloud Pak for Data versions 4.0 or 5.0 should be particularly concerned about CVE-2024-49790 due to its implications for user security.