Executive brief
IBM watsonx.data intelligence is a platform used for managing and analyzing large-scale data workloads. A security flaw allows an authorized user to inject malicious scripts into the web interface, which could be used to steal login credentials or hijack the sessions of other users. This could lead to unauthorized access to sensitive data or administrative functions within the platform.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in IBM watsonx.data intelligence versions 5.2.0 through 5.3.0. The flaw is caused by improper neutralization of user-supplied input during web page generation (CWE-79). An authenticated attacker with low privileges can inject arbitrary JavaScript into the Web UI. When other users view the affected page, the script executes in their browser context, potentially allowing the attacker to disclose session credentials or perform actions on behalf of the victim. The issue is addressed in version 5.3.1.
Affected products
- IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0
Timeline
- 2026-06-30: advisory: Initial publication of CVE-2025-36320 and IBM security bulletin.
- 2026-06-30: patched: Vulnerabilities addressed in version 5.3.1.