CVE-2025-36333: Vulnerabilities found in Watson Data Intelligence
IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow an authenticated user to perform unauthorized actions due to the improper enforcement of behavioral workflow.
Other sources
IBM watsonx.data intelligence could allow an authenticated user to perform unauthorized actions due to the improper enforcement of behavioral workflow.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM watsonx.data intelligenceto a version that resolves this vulnerability.Fixed in 5.3.1 - Compensating control
If upgrading is not immediately possible, restrict access so only authorized users can perform the affected behavioral workflow actions (e.g., tighten role/permission controls for authenticated users).
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36333?
The severity of CVE-2025-36333 is medium with a score of 4.3.
What type of impacts does CVE-2025-36333 have?
CVE-2025-36333 could allow an authenticated user to perform unauthorized actions due to improper enforcement of behavioral workflow.
Which versions of IBM Watson Data Intelligence are affected by CVE-2025-36333?
CVE-2025-36333 affects IBM watsonx.data intelligence versions 5.2.0, 5.2.1, 5.2.2, and 5.3.0.
How can I mitigate CVE-2025-36333?
To mitigate CVE-2025-36333, apply recommended updates provided by IBM for the affected versions of watsonx.data intelligence.
Is CVE-2025-36333 related to user authentication?
Yes, CVE-2025-36333 involves vulnerabilities that can be exploited by an authenticated user.