### [CVE-2024-49785](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-49785) ![](https://img.shields.io/static/v1?label=Product&message=watsonx.ai%20on%20Cloud%20Pak%20for%20Data&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=watsonx.ai&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=1.1%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Version&message=4.8%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-79%20Improper%20Neutralization%20of%20Input%20During%20Web%20Page%20Generation%20(XSS%20or%20'Cross-site%20Scripting')&color=brightgreen) ### Description IBM watsonx.ai 1.1 through 2.0.3 and IBM watsonx.ai on Cloud Pak for Data 4.8 through 5.0.3 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. ### POC #### Reference No PoCs from references. #### Github - https://github.com/fkie-cad/nvd-json-data-feeds