Impact
IBM Cloud Pak for Business Automation is vulnerable to HTML injection. A remote attacker can inject malicious HTML code that, when displayed in a victim’s web browser, executes within the security context of the hosting site. This flaw permits an attacker to deface the web interface, steal session cookies, or run arbitrary scripts, constituting a classic cross‑site scripting vulnerability. The interim fixes that address the vulnerability are: 24.0.0‑IF010, 24.0.1‑IF009, 25.0.0‑IF006, and 26.0.0‑IF001.
Affected Systems
Affected systems include IBM Cloud Pak for Business Automation versions 24.0.0, specifically the releases that have been patched with interim fixes IF010, IF009, IF006, and IF001. The product is distributed in several components, some of which contain open‑source libraries that may not be synchronized across all versions.
Risk and Exploitability
The flaw can be exploited remotely via the web interface; the CVE does not specify whether authentication is required. The CVSS score is 5.4 and the EPSS score is < 1%; the vulnerability is not listed in the CISA KEV catalog. While the risk level is moderate, the potential for cross‑site scripting warrants prompt remediation. Deploying the appropriate are updated mitigates the exposure.
OpenCVE Enrichment