Back

MEDIUM

Multiple Vulnerabilities in IBM Cloud Pak System

Published Feb 4, 2026

Description

IBM Cloud Pak System is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

Affected products

Remediation

Vendor solution

IBM strongly recommends addressing the vulnerabilities now by http://www.ibm.com/support/docview.wss?uid=ibm10887959

For unsupported versions the recommendation is to upgrade to a supported version of the product.

Metrics

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ibm
Published Feb 4, 2026
Updated Feb 5, 2026
Reserved Jul 11, 2023
CISA Vulnrichment
Updated Feb 5, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a