CVE-2025-36145: Multiple Vulnerabilities in watsonx.data
IBM Lakehouse does not properly restrict inbound and outbound connections which could allow an attacker to transfer or modify files without restrictions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM watsonx.data (IBM Lakehouse)to a version that resolves this vulnerability.Fixed in 2.3.x
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36145?
CVE-2025-36145 has a medium severity score of 5.4.
How do I fix CVE-2025-36145?
To fix CVE-2025-36145, upgrade to the latest available version of watsonx.data 2.3.x or watsonx.data on CPD 5.3.x.
What impact does CVE-2025-36145 have on IBM watsonx.data?
CVE-2025-36145 could allow an attacker to transfer or modify files without restrictions due to improper restrictions on inbound and outbound connections.
Which versions of IBM watsonx.data are affected by CVE-2025-36145?
IBM watsonx.data versions 2.2 through 2.3.1 are affected by CVE-2025-36145.
What are the potential risks associated with CVE-2025-36145?
The potential risks include unauthorized file transfers or modifications that could compromise the integrity of data.