Vulnerability Details CVE-2025-0719
IBM Cloud Pak for Data 4.0.0 through 4.8.5 and 5.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 19.1%
CVSS Severity
CVSS v3 Score 6.1
Products affected by CVE-2025-0719
-
cpe:2.3:a:ibm:cloud_pak_for_data:4.0
-
cpe:2.3:a:ibm:cloud_pak_for_data:4.5
-
cpe:2.3:a:ibm:cloud_pak_for_data:4.5.1
-
cpe:2.3:a:ibm:cloud_pak_for_data:4.5.2
-
cpe:2.3:a:ibm:cloud_pak_for_data:4.5.3
-
cpe:2.3:a:ibm:cloud_pak_for_data:4.6
-
cpe:2.3:a:ibm:cloud_pak_for_data:4.6.0
-
cpe:2.3:a:ibm:cloud_pak_for_data:4.6.1
-
cpe:2.3:a:ibm:cloud_pak_for_data:4.6.2
-
cpe:2.3:a:ibm:cloud_pak_for_data:4.6.3
-
cpe:2.3:a:ibm:cloud_pak_for_data:4.6.4
-
cpe:2.3:a:ibm:cloud_pak_for_data:4.6.5
-
cpe:2.3:a:ibm:cloud_pak_for_data:4.6.6
-
cpe:2.3:a:ibm:cloud_pak_for_data:4.7
-
cpe:2.3:a:ibm:cloud_pak_for_data:4.7.1
-
cpe:2.3:a:ibm:cloud_pak_for_data:4.7.2
-
cpe:2.3:a:ibm:cloud_pak_for_data:4.7.3
-
cpe:2.3:a:ibm:cloud_pak_for_data:4.7.4
-
cpe:2.3:a:ibm:cloud_pak_for_data:4.8
-
cpe:2.3:a:ibm:cloud_pak_for_data:4.8.1
-
cpe:2.3:a:ibm:cloud_pak_for_data:4.8.2
-
cpe:2.3:a:ibm:cloud_pak_for_data:4.8.3
-
cpe:2.3:a:ibm:cloud_pak_for_data:4.8.4
-
cpe:2.3:a:ibm:cloud_pak_for_data:4.8.5
-
cpe:2.3:a:ibm:cloud_pak_for_data:5.0