CVE-2025-36321: Vulnerabilities found in Watson Data Intelligence
IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
Other sources
IBM watsonx.data intelligence is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM watsonx.data intelligenceto a version that resolves this vulnerability.Fixed in 5.3.1 - Operational
Upgrade IBM watsonx.data intelligence as soon as possible to address the HTML injection vulnerability affecting versions 5.2.0, 5.2.1, 5.2.2, and 5.3.0.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36321?
The severity of CVE-2025-36321 is rated as medium with a score of 5.7.
What is the risk associated with CVE-2025-36321?
The risk associated with CVE-2025-36321 is classified as low with a risk score of 33.
How do I fix CVE-2025-36321?
To fix CVE-2025-36321, update your IBM watsonx.data intelligence software to the latest version available.
What type of attack can be performed using CVE-2025-36321?
CVE-2025-36321 allows for HTML injection attacks, enabling remote attackers to execute malicious HTML code in the victim's web browser.
Which versions of IBM watsonx.data intelligence are affected by CVE-2025-36321?
CVE-2025-36321 affects IBM watsonx.data intelligence versions 5.2.0, 5.2.1, 5.2.2, and 5.3.0.