CVE-2026-17467: Vulnerabilities exists in IBM Cloud Pak for Data System
IBM Cloud Pak for Data System (Yosemite 1.0) 3.0.5.2 could allow a remote attacker to obtain sensitive information due to the use of weak or deprecated cryptographic protocols.
Other sources
IBM Cloud Pak for Data System (Yosemite 1.0) could allow a remote attacker to obtain sensitive information due to the use of weak or deprecated cryptographic protocols.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Cloud Pak for Data System (Yosemite 1.0)to a version that resolves this vulnerability.Fixed in 3.0.5.3-WS-ICPDS-NRS-fp346929Patch 3.0.5.3-WS-ICPDS-NRS-fp346929 - Upgrade
Upgrade
IBM Cloud Pak for Data System (Yosemite 1.0)to a version that resolves this vulnerability.Fixed in 3.0.5.3-WS-ICPDS-NRS-fp346929
Event History
Frequently Asked Questions
Who can exploit this issue?
A remote attacker can exploit the weak or deprecated cryptographic protocols to obtain sensitive information. The vector is network-based and requires no privileges or user interaction.
What security impact is documented?
The documented impact is disclosure of sensitive information. Integrity impact is rated low, while no availability impact is indicated.
Which release is specifically identified as affected?
IBM Cloud Pak for Data System (Yosemite 1.0) version 3.0.5.2 is specifically identified. The advisory text also states that IBM Cloud Pak for Data System (Yosemite 1.0) is affected, without providing additional version detail.