CVE-2025-36145

IBM watsonx.data 2.2 through 2.3.1 IBM Lakehouse does not properly restrict inbound and outbound connections which could allow an attacker to transfer or modify files without restrictions.
References
Link Resource
https://www.ibm.com/support/pages/node/7272498 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:ibm:watsonx.data:*:*:*:*:*:*:*:*

History

01 Jun 2026, 17:24

Type Values Removed Values Added
First Time Ibm watsonx.data
Ibm
References () https://www.ibm.com/support/pages/node/7272498 - () https://www.ibm.com/support/pages/node/7272498 - Vendor Advisory
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:ibm:watsonx.data:*:*:*:*:*:*:*:*

26 May 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-26 17:16

Updated : 2026-06-01 17:24


NVD link : CVE-2025-36145

Mitre link : CVE-2025-36145

CVE.ORG link : CVE-2025-36145


JSON object : View

Products Affected

ibm

  • watsonx.data
CWE
CWE-923

Improper Restriction of Communication Channel to Intended Endpoints

NVD-CWE-noinfo