CVE-2025-12530: Vulnerabilities found in Watson Data Intelligence
IBM watsonx.data intelligence 5.2.2, 5.3.0, 5.3.1, 5.3.1 through patch-1 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.
Other sources
IBM watsonx.data intelligence transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM watsonx.data intelligenceto a version that resolves this vulnerability.Fixed in 5.3.1-patch3Patch patch-1 - Compensating control
Because IBM watsonx.data intelligence versions 5.2.2, 5.3.0, 5.3.1, and 5.3.1 through patch-1 transmit data in clear text, mitigate the man-in-the-middle risk by ensuring network paths are protected (e.g., use trusted/private network paths or enforce protections to prevent MITM) until the upgrade to IBM’s advised fix is completed.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12530?
CVE-2025-12530 has a medium severity rating of 5.9.
What does CVE-2025-12530 entail?
CVE-2025-12530 describes vulnerabilities in IBM watsonx.data intelligence that transmit data in clear text, exposing sensitive information to potential man-in-the-middle attacks.
How do I fix CVE-2025-12530?
To mitigate CVE-2025-12530, update to a secure version of IBM watsonx.data intelligence that addresses the clear text transmission issue.
What are the potential risks associated with CVE-2025-12530?
CVE-2025-12530 allows attackers to intercept sensitive data during transmission, leading to data breaches.
Which versions of IBM watsonx.data intelligence are affected by CVE-2025-12530?
CVE-2025-12530 affects IBM watsonx.data intelligence versions 5.2.2, 5.3.0, and 5.3.1 up to patch-1.