IBM OpenPages HTML Injection Vulnerability

Vulnerability

A HTML injection vulnerability has been identified in IBM OpenPages versions 9.1 and 9.0. This issue allows remotely authenticated attackers to inject malicious HTML, which is executed in the context of the victim's web browser and the hosting site.

Impact

Exploitation of this vulnerability allows for HTML injection, where injected content is executed in the context of the user's browser.

Remediation

Users of IBM OpenPages 9.1.2 can download the update from the IBM Support page for version 9.1.2. For IBM OpenPages 9.0, users should apply FixPack 5 (9.0.0.5) followed by Interim Fix 5 (9.0.0.5.6). Both updates are available on the IBM Support pages for version 9.0.0.5 and 9.0.0.5.6.

Added: Oct 27, 2025, 3:20 PM
Updated: Oct 27, 2025, 3:20 PM

Vulnerability Rating

Custom Algorithm
spread
1.4
impact
1.7
exploitability
4.6
remediation
7.7
relevance
0.9
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.