Junglewise Threat Intelligence

CVE-2025-36319: IBM watsonx.data intelligence denial of service via improper throttling

CVE-2025-36319 · Severity: medium · CVSS 4.3 · Published 2026-06-30

Technologies: IBM Watsonx.Data Intelligence. Vendors: IBM.

Executive brief

IBM watsonx.data intelligence is a platform used for managing and analyzing large-scale data workloads. A vulnerability in this system allows a logged-in user to send a specifically crafted request that overwhelms the system's resources. This can lead to a temporary service outage, preventing other users from accessing the data platform and disrupting business operations.

Technical details

IBM watsonx.data intelligence is vulnerable to a denial of service (DoS) attack due to improper allocation of resource throttling (CWE-770). An authenticated attacker with network access can send a specially crafted HTTP request that consumes excessive system resources. This occurs because the application fails to properly limit or throttle specific resource-intensive requests. Successful exploitation allows the attacker to cause a temporary denial of service for legitimate users. The issue is addressed in version 5.3.1.

Affected products

  • IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: advisory

References

Related threats