Executive brief
IBM Integrated Analytics System uses predictable salt values in its Magneto component's cryptographic operations, weakening encryption and hashing protections. An attacker could exploit this to perform precomputation attacks (such as rainbow table attacks) to decrypt and access highly sensitive information stored within the system, potentially compromising customer data confidentiality.
Technical details
The vulnerability is a use of a one-way hash without proper salt (CWE-759) located in the resmgr.py module of the Magneto resource manager component. The predictable salt value undermines the effectiveness of hashing and encryption mechanisms, enabling attackers to perform precomputation attacks such as rainbow table attacks without requiring authentication or user interaction. An attacker with network access can decrypt highly sensitive information and compromise data confidentiality and integrity. The vulnerability affects versions 1.0.0.0 through 1.0.31.0, and a fix is available in version 1.0.32.0.
Affected products
- IBM Integrated Analytics System 1.0.0.0 through 1.0.31.0
Timeline
- 2026-08-26: disclosed: Initial publication of security bulletin CVE-2025-36271
- 2026-08-26: patched: Fix released in version 1.0.32.0 with fix pack 1.0.32.0-IM-IIAS-fp402