Junglewise Threat Intelligence

CVE-2025-12530: IBM watsonx.data intelligence cleartext transmission of sensitive data

CVE-2025-12530 · Severity: medium · CVSS 5.9 · Published 2026-06-30

Technologies: IBM Watsonx.Data Intelligence. Vendors: IBM.

Executive brief

IBM watsonx.data intelligence is a platform used for managing and analyzing large-scale data sets. A security flaw in certain versions allows sensitive information to be transmitted without encryption. An attacker positioned on the same network could intercept this traffic to steal confidential data, potentially compromising business operations or privacy.

Technical details

IBM watsonx.data intelligence versions 5.2.2 through 5.3.1 patch-1 are vulnerable to cleartext transmission of sensitive information (CWE-319). The vulnerability stems from a failure to enforce encrypted communication channels for certain data transfers. A remote attacker with the ability to intercept network traffic (Man-in-the-Middle) can capture sensitive data as it passes between the application and other endpoints. Exploitation requires the attacker to be positioned on the network path but does not require prior authentication. IBM has addressed this issue in Watson Data Intelligence version 5.3.1-patch3.

Affected products

  • IBM watsonx.data intelligence 5.2.2, 5.3.0, 5.3.1, 5.3.1 through patch-1

Timeline

  • 2026-06-30: advisory: Initial advisory publication by IBM and NVD.
  • 2026-06-30: disclosed
  • 2026-06-30: patched: Fixed in version 5.3.1-patch3.

References

Related threats