Junglewise Threat Intelligence

CVE-2025-36321: IBM watsonx.data intelligence HTML injection

CVE-2025-36321 · Severity: medium · CVSS 5.7 · Published 2026-06-30

Technologies: IBM Watsonx.Data Intelligence. Vendors: IBM.

Executive brief

IBM watsonx.data intelligence is a platform used for managing and analyzing large-scale data workloads. A security vulnerability in certain versions allows a remote attacker to inject malicious HTML code into the application. If a user views the affected content, the malicious code could execute in their browser, potentially allowing the attacker to access sensitive information within the user's session.

Technical details

IBM watsonx.data intelligence versions 5.2.0 through 5.3.0 are vulnerable to HTML injection (CWE-80). The vulnerability stems from improper neutralization of script-related HTML tags in web pages. A remote attacker with low privileges can inject malicious HTML code that, when viewed by a victim, executes within the security context of the hosting site. This can lead to the disclosure of sensitive information. The issue is addressed in Watson Data Intelligence version 5.3.1.

Affected products

  • IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0

Timeline

  • 2026-06-30: disclosed: Initial advisory publication date
  • 2026-06-30: advisory: NVD record published

References

Related threats