CVE-2025-33110: IBM OpenPages Vulnerable to HTML Injection
IBM OpenPages 9.1, and 9.0 with Watson is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
Other sources
IBM OpenPages with Watson is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM OpenPagesto a version that resolves this vulnerability.Fixed in 9.1.2 - Upgrade
Upgrade
IBM OpenPagesto a version that resolves this vulnerability.Fixed in 9.0.0.5 - Upgrade
Upgrade
IBM OpenPagesto a version that resolves this vulnerability.Fixed in 9.0.0.5.7Patch 9.0.0.5 Interim Fix 7 - Upgrade
Upgrade
IBM OpenPagesto a version that resolves this vulnerability.Fixed in 9.1
Event History
Frequently Asked Questions
What is the severity of CVE-2025-33110?
CVE-2025-33110 is considered a high severity vulnerability due to its potential for HTML injection and exploitation in victim's browsers.
How do I fix CVE-2025-33110?
To fix CVE-2025-33110, you should apply the available patches for IBM OpenPages version 9.0 and 9.1.
Who is affected by CVE-2025-33110?
CVE-2025-33110 affects users of IBM OpenPages versions 9.0 and 9.1 with Watson implementation.
What are the risks associated with CVE-2025-33110?
The risks of CVE-2025-33110 include potential unauthorized access and execution of malicious HTML code in users' browsers.
What products are implicated in CVE-2025-33110?
The products implicated in CVE-2025-33110 are IBM OpenPages version 9.0 and version 9.1.