CVE-2025-36290: IBM Integrated Analytics System (IIAS) is affected by improper SSL/TLS certificate validation vulnerability in JWT service component
IBM Integrated Analytics System 1.0.0.0 through 1.0.31.0 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information using man in the middle techniques.
Other sources
IBM Integrated Analytics System does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information using man in the middle techniques.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Integrated Analytics Systemto a version that resolves this vulnerability.Fixed in 1.0.32.0Patch 1.0.32.0-IM-IIAS-fp402
Event History
Frequently Asked Questions
Which IIAS versions are affected?
IBM Integrated Analytics System versions 1.0.0.0 through 1.0.31.0 are affected.
What would an attacker need to exploit this issue?
An attacker would need to position themselves to perform a man-in-the-middle attack against TLS communications involving the JWT service component. The provided vector indicates exploitation is network-based, requires high attack complexity, and does not require privileges or user interaction.
What is the likely impact of successful exploitation?
A successful man-in-the-middle attack could allow an attacker to obtain sensitive information. The supplied severity vector indicates confidentiality impact is high, while integrity and availability impacts are not identified.