CVE-2025-36320: Vulnerabilities found in Watson Data Intelligence
IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM watsonx.data intelligence is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM watsonx.data intelligenceto a version that resolves this vulnerability.Fixed in 5.3.1 - Compensating control
Mitigate stored cross-site scripting in the Watson Data Intelligence Web UI by restricting access so that only trusted authenticated users can use the Web UI (reducing exposure to embedded arbitrary JavaScript).
- Operational
Review for any stored injected content in the Watson Data Intelligence Web UI and remove/clean it after upgrading, to prevent continued JavaScript execution in trusted sessions.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36320?
The severity of CVE-2025-36320 is classified as medium with a score of 6.4.
How do I fix CVE-2025-36320?
To fix CVE-2025-36320, update IBM watsonx.data intelligence to the latest version that addresses this vulnerability.
What type of vulnerability is CVE-2025-36320?
CVE-2025-36320 is a stored cross-site scripting (XSS) vulnerability.
Who is affected by CVE-2025-36320?
Authenticated users of IBM watsonx.data intelligence versions 5.2.0, 5.2.1, 5.2.2, and 5.3.0 are affected by CVE-2025-36320.
What are the potential consequences of CVE-2025-36320?
CVE-2025-36320 can lead to the disclosure of credentials and alter the intended functionality of the Web UI.