CVE-2025-36328: Error Message Containing Sensitive Information found in Watson Data Intelligence
IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
Other sources
IBM watsonx.data intelligence could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM watsonx.data intelligenceto a version that resolves this vulnerability.Fixed in 5.3.1
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36328?
The severity of CVE-2025-36328 is medium, with a base score of 4.3.
What types of systems are affected by CVE-2025-36328?
CVE-2025-36328 affects versions 5.2.0, 5.2.1, 5.2.2, and 5.3.0 of IBM watsonx.data intelligence.
What does CVE-2025-36328 allow an attacker to do?
CVE-2025-36328 allows a remote attacker to obtain sensitive information from detailed technical error messages returned in the browser.
How can CVE-2025-36328 be mitigated?
To mitigate CVE-2025-36328, configure the software to avoid showing detailed technical error messages in the browser.
What is the impact of CVE-2025-36328 on systems?
The impact of CVE-2025-36328 could potentially lead to further attacks by leaking sensitive information.