Executive brief
IBM Cloud Pak for Business Automation contains an HTML injection vulnerability that allows attackers to inject malicious code into web pages. When a victim views an affected page, the injected code executes in their browser with access to sensitive session data and site functionality, potentially leading to data theft or unauthorized actions.
Technical details
The vulnerability is an HTML injection flaw in IBM Cloud Pak for Business Automation that allows remote attackers to inject arbitrary HTML and JavaScript code into web pages without proper input validation or output encoding. The injected code executes client-side in the victim's browser within the security context of the hosting application, enabling session hijacking, credential theft, and malicious actions performed on behalf of the user. No authentication is required to exploit this vulnerability as it operates at the presentation layer. IBM has released patches and iFixes to address this issue as of August 2026.
Affected products
- IBM Cloud Pak for Business Automation
Timeline
- 2026-09-15: disclosed