IBM watsonx.ai是美国国际商业机器(IBM)公司的一个库。允许在 IBM Cloud 和 IBM Cloud for Data 上使用 watsonx.ai 服务。 IBM watsonx.ai 1.1版本至2.0.3版本和IBM watsonx.ai on Cloud Pak for Data 4.8版本至5.0.3版本存在跨站脚本漏洞。攻击者利用该漏洞可以在 Web UI 中嵌入任意 JavaScript 代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| IBM | watsonx.ai | 1.1 ~ 2.0.3 |
cpe:2.3:a:ibm:watsonx.ai:1.1:*:*:*:*:*:*:*
|
|
| IBM | watsonx.ai on Cloud Pak for Data | 4.8 ~ 5.0.3 |
cpe:2.3:a:ibm:watsonx.ai_on_cloud_pak_for_data:4.8:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-51456 | 5.9 MEDIUM | IBM Robotic Process Automation information disclosure |
| CVE-2021-29669 | 5.4 MEDIUM | IBM Jazz Foundation cross-site scripting |
No comments yet