logo

IBM Watsonx.ai Vulnerability Let Attackers Trigger XSS Attacks

ID: a94b0774-2e3f-5a46-8140-be8b020d8152

STIX ID: report--a94b0774-2e3f-5a46-8140-be8b020d8152

Feed Name: GBHackers

Threat Score
45/100

Date Published: 2025-01-13

Date Updated: 2026-04-22

Author: Divya

...
...

A cross-site scripting vulnerability (CVE-2024-49785, CWE-79, CVSS 5.4) was disclosed in IBM watsonx.ai and its integration with IBM Cloud Pak for Data, affecting specified versions (watsonx.ai 1.1–2.0.3; watsonx.ai on Cloud Pak for Data 4.8–5.0.3). Authenticated users can inject arbitrary JavaScript, potentially enabling credential disclosure; IBM published fixed versions (watsonx.ai 2.1.0+ and Cloud Pak build 5.1.0+) and recommends upgrading and subscribing to security notifications. Disclosed January 10, 2025, the issue is remotely exploitable but requires some user interaction.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.