CVE-2025-36271: IBM Integrated Analytics System (IIAS) is affected by a predictable salt vulnerability in Magneto component
IBM Integrated Analytics System 1.0.0.0 through 1.0.31.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
Other sources
IBM Integrated Analytics System uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Integrated Analytics System (IIAS)to a version that resolves this vulnerability.Fixed in 1.0.32.0Patch 1.0.32.0-IM-IIAS-fp402
Event History
Frequently Asked Questions
Which IIAS versions are affected?
IBM Integrated Analytics System versions 1.0.0.0 through 1.0.31.0 are affected.
What could an attacker gain from exploiting this issue?
The weakness could allow an attacker to decrypt highly sensitive information.
Does exploitation require authentication or user interaction?
The provided vector indicates that no privileges and no user interaction are required. Exploitation is network-accessible, but has high attack complexity.