CVE-2025-36336: Transmission of Sensitive Information found in Watson Data Intelligence
IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.
Other sources
IBM watsonx.data intelligence transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM watsonx.data intelligenceto a version that resolves this vulnerability.Fixed in 5.3.1 - Compensating control
For IBM watsonx.data intelligence affected versions (5.2.0, 5.2.1, 5.2.2, 5.3.0), mitigate man-in-the-middle risk by protecting data-in-transit (e.g., restrict and secure network paths/enable appropriate transport security) until you upgrade, since the product transmits data in clear text.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36336?
The severity of CVE-2025-36336 is rated as medium with a CVSS score of 5.9.
What kind of information is transmitted in clear text in CVE-2025-36336?
CVE-2025-36336 involves the transmission of sensitive data, potentially allowing unauthorized access to confidential information.
How do I fix CVE-2025-36336?
To mitigate CVE-2025-36336, it is recommended to enable encryption for data transmission to prevent interception.
What versions of IBM watsonx.data intelligence are affected by CVE-2025-36336?
CVE-2025-36336 affects IBM watsonx.data intelligence versions 5.2.0, 5.2.1, 5.2.2, and 5.3.0.
What is a man-in-the-middle attack in the context of CVE-2025-36336?
A man-in-the-middle attack in the context of CVE-2025-36336 refers to an attacker intercepting and possibly altering the communication between users and the IBM watsonx.data intelligence service.