CVE-2025-36336: Cleartext Transmission of Sensitive Information in Watson Data Intelligence
IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.
Other sources
IBM watsonx.data intelligence transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM watsonx.data intelligenceto a version that resolves this vulnerability.Fixed in 5.3.1 - Compensating control
If immediate upgrade is not possible, mitigate man-in-the-middle risk by using network controls appropriate for preventing/limiting MITM attacks (e.g., restrict and protect traffic paths until upgrading).
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36336?
The severity of CVE-2025-36336 is rated as medium with a CVSS score of 5.9.
What kind of information is transmitted in clear text in CVE-2025-36336?
CVE-2025-36336 involves the transmission of sensitive data, potentially allowing unauthorized access to confidential information.
How do I fix CVE-2025-36336?
To mitigate CVE-2025-36336, it is recommended to enable encryption for data transmission to prevent interception.
What versions of IBM watsonx.data intelligence are affected by CVE-2025-36336?
CVE-2025-36336 affects IBM watsonx.data intelligence versions 5.2.0, 5.2.1, 5.2.2, and 5.3.0.
What is a man-in-the-middle attack in the context of CVE-2025-36336?
A man-in-the-middle attack in the context of CVE-2025-36336 refers to an attacker intercepting and possibly altering the communication between users and the IBM watsonx.data intelligence service.