PT-2025-27446 · Ibm · Ibm Cloud Pak System

Published

2025-06-30

·

Updated

2025-08-14

·

CVE-2025-2895

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions: IBM Cloud Pak System versions 2.3.3.6 through 2.3.4.1 iFix1
Description: The issue allows a remote attacker to inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. This is a result of an HTML injection flaw.
Recommendations: For IBM Cloud Pak System versions 2.3.3.6 through 2.3.4.1 iFix1, update to a version that includes the fix for this issue to prevent HTML injection attacks.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2025-09712
CVE-2025-2895

Affected Products

Ibm Cloud Pak System