Executive brief
IBM Integrated Analytics System is used for data analytics and integration across enterprise environments. The system's JWT authentication service fails to validate TLS certificates, allowing attackers positioned on the network to intercept and read sensitive authentication tokens and other encrypted communications without being detected.
Technical details
The vulnerability is an improper certificate validation flaw (CWE-295) in the apjwtservice.py module of the JWT service component. SSL/TLS server certificate validation is disabled, making connections susceptible to man-in-the-middle (MITM) attacks. An attacker with network access can intercept encrypted communications between the client and the JWT service, potentially exposing sensitive information and authentication tokens. The vulnerability requires network-level access but no authentication or user interaction. A patch is available in version 1.0.32.0 (specifically firmware package 1.0.32.0-IM-IIAS-fp402).
Affected products
- IBM Integrated Analytics System 1.0.0.0 through 1.0.31.0
Timeline
- 2026-08-26: disclosed
- 2026-08-26: patched: Fix available in version 1.0.32.0