CVE-2025-36319: Vulnerabilities found in Watson Data Intelligence
IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow an authenticated user to cause a temporary denial using a specially crafted HTTP request due to improper allocation of resource throttling.
Other sources
IBM watsonx.data intelligence could allow an authenticated user to cause a temporary denial using a specially crafted HTTP request due to improper allocation of resource throttling.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM watsonx.data intelligenceto a version that resolves this vulnerability.Fixed in 5.3.1Patch 5.3.1 - Compensating control
Apply the advice to upgrade as soon as possible to mitigate the temporary denial of service caused by improper allocation of resource throttling in Watson Data Intelligence (authenticated users with specially crafted HTTP requests).
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36319?
The severity of CVE-2025-36319 is categorized as medium with a CVSS score of 4.3.
How do I fix CVE-2025-36319?
To mitigate CVE-2025-36319, ensure you update IBM watsonx.data intelligence to the latest version where the vulnerability is patched.
What systems are affected by CVE-2025-36319?
CVE-2025-36319 affects IBM watsonx.data intelligence versions 5.2.0, 5.2.1, 5.2.2, and 5.3.0.
What type of attacks does CVE-2025-36319 allow?
CVE-2025-36319 allows authenticated users to initiate a temporary denial of service through specially crafted HTTP requests.
What is the impact of CVE-2025-36319?
The impact of CVE-2025-36319 is a potential temporary denial of service due to improper allocation of resource throttling.