CVE-2025-36324: Vulnerabilities found in Watson Data Intelligence
IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 s vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
Other sources
IBM watsonx.data intelligence s vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM watsonx.data intelligenceto a version that resolves this vulnerability.Fixed in 5.3.1
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36324?
The severity of CVE-2025-36324 is medium, rated at 4.3 on the CVSS scale.
What type of vulnerability is identified in CVE-2025-36324?
CVE-2025-36324 identifies a server-side request forgery (SSRF) vulnerability.
Who can be affected by CVE-2025-36324?
Authenticated attackers are the ones who can exploit CVE-2025-36324.
How can I mitigate CVE-2025-36324?
Mitigation for CVE-2025-36324 involves updating IBM watsonx.data intelligence to a patched version that resolves the SSRF vulnerability.
What potential risks are associated with CVE-2025-36324?
Exploitation of CVE-2025-36324 may lead to unauthorized requests from the system, potentially enabling network enumeration or further attacks.