CyberRota Analysis
AI-GeneratedIBM Cloud Pak for Business Automation is susceptible to stored cross-site scripting, enabling authenticated users to inject arbitrary JavaScript into the Web UI. This could compromise the integrity of user sessions, potentially leading to credential disclosure. Organizations utilizing this platform should prioritize remediation to mitigate the risk of exploitation.
CVE
CVE-2026-12750
Severity
MEDIUM
CVSS
6.4
EPSS
0.25%
Java
Original NVD Description
IBM Cloud Pak for Business Automation is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.