Executive brief
IBM watsonx.data intelligence is a platform used for managing and analyzing large-scale data workloads. A security flaw in its web interface allows an authenticated user to inject malicious scripts that could be executed in the browsers of other users. This could lead to the theft of login credentials or unauthorized actions being performed within a user's active session.
Technical details
IBM watsonx.data intelligence versions 5.2.0 through 5.3.0 are vulnerable to cross-site scripting (XSS) due to improper neutralization of user-supplied input during web page generation (CWE-79). An authenticated attacker can inject arbitrary JavaScript code into the Web UI. If a victim views the affected page, the script executes within the context of their browser session, potentially allowing the attacker to disclose sensitive information such as session credentials or alter application functionality. The vulnerability is addressed in version 5.3.1.
Affected products
- IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0
Timeline
- 2026-06-30: advisory: Initial advisory published by IBM and NVD.
- 2026-06-30: patched: Vulnerability addressed in version 5.3.1.