1 results (0.002 seconds)
CVSS: 5.5EPSS: 0%CPEs: 2EXPL: 0

CVE-2024-49785 – IBM watsonx.ai cross-site scripting
https://notcve.org/view.php?id=CVE-2024-49785
12 Jan 2025 — IBM watsonx.ai 1.1 through 2.0.3 and IBM watsonx.ai on Cloud Pak for Data 4.8 through 5.0.3 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. • https://www.ibm.com/support/pages/node/7180723 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •