CVE-2025-36327: Vulnerabilities found in Watson Data Intelligence
IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow an authenticated user to bypass security controls and perform unauthorized actions due to client-side enforcement of sever-side security.
Other sources
IBM watsonx.data intelligence could allow an authenticated user to bypass security controls and perform unauthorized actions due to client-side enforcement of sever-side security.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM watsonx.data intelligenceto a version that resolves this vulnerability.Fixed in 5.3.1 - Compensating control
Until you upgrade, restrict access so only authorized users can access Watson Data Intelligence and its endpoints, since authenticated users may bypass server-side security controls via client-side enforcement.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36327?
CVE-2025-36327 has a medium severity rating of 6.5.
How do I fix CVE-2025-36327?
To fix CVE-2025-36327, upgrade IBM watsonx.data intelligence to the latest version.
What kind of vulnerabilities does CVE-2025-36327 present?
CVE-2025-36327 allows authenticated users to bypass security controls due to client-side enforcement of server-side security.
Which versions of IBM watsonx.data intelligence are affected by CVE-2025-36327?
Versions 5.2.0, 5.2.1, 5.2.2, and 5.3.0 of IBM watsonx.data intelligence are affected by CVE-2025-36327.
What actions can be performed due to the vulnerability identified in CVE-2025-36327?
CVE-2025-36327 allows authenticated users to perform unauthorized actions by bypassing security controls.