Executive brief
IBM watsonx.data intelligence is a platform used for managing and analyzing large-scale data sets. A vulnerability in certain versions could allow a remote user to view detailed technical error messages in their web browser. These messages may contain sensitive system information that could be used to facilitate further, more targeted attacks against the organization's data infrastructure.
Technical details
The vulnerability is classified as CWE-209 (Generation of Error Message Containing Sensitive Information). It occurs when the application returns overly verbose technical details in error responses to the client's browser. An authenticated remote attacker can trigger these errors to leak internal system information. This information disclosure can be leveraged to map the internal environment or identify further vulnerabilities. IBM has addressed this issue in Watson Data Intelligence version 5.3.1.
Affected products
- IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0
Timeline
- 2026-06-30: disclosed
- 2026-06-30: advisory
- 2026-06-30: patched: Fixed in version 5.3.1