CVE-2025-36121: HTML Injection Vulnerability in a Specific URL Endpoint of the IBM OpenPages Application
IBM OpenPages 9.1 and 9.0 is vulnerable to HTML injection. A remotely authenticated attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
Other sources
IBM OpenPages with Watson is vulnerable to HTML injection. A remotely authenticated attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM OpenPagesto a version that resolves this vulnerability.Fixed in 9.1.2 - Upgrade
Upgrade
IBM OpenPagesto a version that resolves this vulnerability.Fixed in 9.0.0.5.6
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36121?
CVE-2025-36121 is considered a medium severity vulnerability due to the potential for HTML injection by an authenticated attacker.
How do I fix CVE-2025-36121?
To fix CVE-2025-36121, you should apply the latest patches for IBM OpenPages version 9.0 and 9.1.
What are the affected versions for CVE-2025-36121?
CVE-2025-36121 affects IBM OpenPages versions 9.0 and 9.1.
Who is affected by CVE-2025-36121?
Organizations using IBM OpenPages 9.0 and 9.1 are susceptible to CVE-2025-36121.
Can CVE-2025-36121 be exploited remotely?
Yes, CVE-2025-36121 can be exploited remotely by an authenticated attacker injecting malicious HTML code.