Executive brief
IBM watsonx.data intelligence, a platform for managing and analyzing large-scale data, contains a security flaw that could allow a registered user to bypass intended restrictions. By manipulating data on their own computer rather than the server, a user could perform actions they are not authorized to do. This could lead to unauthorized changes to data or system configurations, potentially compromising the integrity of the platform's operations.
Technical details
IBM watsonx.data intelligence is vulnerable to a security bypass (CWE-602) where security controls are enforced on the client-side rather than the server-side. An authenticated attacker with network access can exploit this by manipulating client-side requests to bypass intended restrictions and perform unauthorized actions. The vulnerability affects versions 5.2.0, 5.2.1, 5.2.2, and 5.3.0. According to the vendor advisory, these issues are addressed in Watson Data Intelligence version 5.3.1. The exploit requires low privileges and no user interaction, primarily impacting system integrity.
Affected products
- IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0
Timeline
- 2026-06-30: advisory: NVD and IBM published the advisory details.
- 2026-06-30: patched: IBM released version 5.3.1 to address the vulnerability.