PT-2025-39409 · Ibm · Ibm Watson Studio+1

Jubilian Ho Hong Yi

·

Published

2025-09-25

·

Updated

2025-10-07

·

CVE-2025-33116

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions IBM Watson Studio versions 4.0 through 5.2.0 on Cloud Pak for Data
Description An authenticated user can embed arbitrary JavaScript code in the Web UI, potentially altering intended functionality and leading to credentials disclosure within a trusted session.
Recommendations Update to a version later than 5.2.0.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-33116

Affected Products

Cloud Pak For Data
Ibm Watson Studio