Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
The product needs to be installed or upgraded to the latest available level watsonx.data 2.2.1 or watsonx.data on CPD 5.2.1 Installation/upgrade instructions can be found here: https://www.ibm.com/docs/en/watsonx/watsonxdata/2.2.x?topic=deployment-installing https://www.ibm.com/docs/en/software-hub/5.2.x .
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-29859 | IBM Lakehouse (watsonx.data 2.2) is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. |
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7245387 |
|
Thu, 25 Sep 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | ||
| Vendors & Products |
Ibm watsonx.data.
|
Thu, 25 Sep 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ibm watsonx.data.
|
|
| CPEs | cpe:2.3:a:ibm:watsonx.data.:2.2:*:*:*:*:*:*:* | |
| Vendors & Products |
Ibm watsonx.data.
|
Fri, 19 Sep 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 18 Sep 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Lakehouse (watsonx.data 2.2) is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Title | IBM watsonx.data cross-site scripting | |
| First Time appeared |
Ibm
Ibm watsonx.data |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:ibm:watsonx.data:2.2:*:*:*:*:*:*:* | |
| Vendors & Products |
Ibm
Ibm watsonx.data |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-09-19T17:09:30.745Z
Reserved: 2025-04-15T21:16:19.008Z
Link: CVE-2025-36139
Updated: 2025-09-19T17:00:57.441Z
Status : Analyzed
Published: 2025-09-18T16:15:50.310
Modified: 2025-09-25T16:16:36.910
Link: CVE-2025-36139
No data.
OpenCVE Enrichment
No data.
EUVD