Executive brief
IBM watsonx.data intelligence is a platform used for managing and analyzing large-scale data workloads. A security vulnerability exists that allows a logged-in user to trick the system into making unauthorized network requests. This could allow an attacker to map out internal network services or access restricted information that is not normally visible from outside the corporate network.
Technical details
IBM watsonx.data intelligence versions 5.2.0 through 5.3.0 are vulnerable to Server-Side Request Forgery (SSRF) via CWE-918. An authenticated attacker with network access can exploit this vulnerability to send unauthorized requests from the server's context. This can be used for internal network enumeration, port scanning, or facilitating further attacks against internal infrastructure that is otherwise unreachable. The vulnerability is addressed in version 5.3.1.
Affected products
- IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0
Timeline
- 2026-06-30: disclosed
- 2026-06-30: advisory