CVE-2024-49790
Executive Summary
IBM Watson Studio on Cloud Pak for Data 4.0/5.0 is vulnerable to authenticated XSS. Attackers can inject arbitrary JavaScript into the Web UI, potentially altering functionality and exposing credentials within a trusted session. No current CISA KEV listing.
Authoritative CVE Metadata - CVSS Base Score: 5.4 (MEDIUM) - Published: 2025-08-28T14:15:43.257 - Last Modified: 2026-09-26T21:10:00.130
Original Description: IBM Watson Studio on Cloud Pak for Data 4.0 and 5.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
"When anger use your energy to do something productive."
— C. Pulsifer