Impact
IBM Cloud Pak for Business Automation contains a persistent stored cross‑site scripting flaw that permits an authenticated user to inject arbitrary JavaScript into the web interface. The injected script runs in the victim’s browser with the victim’s credentials; it can modify the user interface or capture sensitive data, including credentials, that the user is authorized to see. The weakness is a classic example of improper input validation and storage, classified as CWE‑79. This flaw directly enables credential or data theft within a trusted session.
Affected Systems
IBM Cloud Pak for Business Automation is affected in releases 24.0.0, 24.0.1, 25.0.0 and 26.0.0, including the interim fix points listed for each version. Open‑source components integrated into the product can also introduce additional XSS vectors that may not be updated synchronously.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity. The EPSS score < 1% points to a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to be authenticated, meaning the attacker must possess valid credentials or leverage another vulnerability to gain access. Once authenticated, a malicious script can execute in users’ browsers, potentially exposing credentials or facilitating other malicious activity. The risk remains moderate, especially where privileged user accounts are not tightly controlled.
OpenCVE Enrichment