CVE-2025-36323: Vulnerabilities found in Watson Data Intelligence
IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM watsonx.data intelligence is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM watsonx.data intelligenceto a version that resolves this vulnerability.Fixed in 5.3.1
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36323?
CVE-2025-36323 has a medium severity rating of 5.4.
How do I fix CVE-2025-36323?
To mitigate CVE-2025-36323, update to a patched version of IBM watsonx.data intelligence that addresses the XSS vulnerability.
What type of vulnerability is CVE-2025-36323?
CVE-2025-36323 is a cross-site scripting (XSS) vulnerability.
Who is affected by CVE-2025-36323?
Authenticated users of IBM watsonx.data intelligence versions 5.2.0 through 5.3.0 may be affected by CVE-2025-36323.
What is the potential impact of CVE-2025-36323?
CVE-2025-36323 can lead to credentials disclosure within a trusted session due to the embedding of arbitrary JavaScript code.