Impact
IBM Cloud Pak for Business Automation is vulnerable to a stored cross‑site scripting flaw. An authenticated user can embed arbitrary JavaScript into the Web UI, which may alter the intended functionality and potentially expose user credentials within a trusted session. The weakness is formally classified as CWE-79.
Affected Systems
The vulnerability affects IBM Cloud Pak for Business Automation versions 24.0.0, 24.0.1, 25.0.0, and 26.0.0, each with their respective interim fix releases (e.g., 24.0.0‑IF009, 24.0.1‑IF008, 25.0.0‑IF005, 26.0.0‑IF001). Open source libraries may be present in sub‑components of the package; updates to these libraries are not always synchronized across all components.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate risk. The EPSS score of <1% shows a very low probability of exploitation. The vulnerability is not listed in CISA KEV, indicating no known active exploitation. Attack requires an authenticated user with access to the Web UI to inject malicious script; once executed, the attacker could harvest session cookies or other credentials. Proper access controls and keeping the system patched reduce this risk.
OpenCVE Enrichment