Junglewise Threat Intelligence

CVE-2025-36333: IBM watsonx.data intelligence improper workflow enforcement

CVE-2025-36333 · Severity: medium · CVSS 4.3 · Published 2026-06-30

Technologies: IBM Watsonx.Data Intelligence. Vendors: IBM.

Executive brief

IBM watsonx.data intelligence is a platform used for managing and analyzing large-scale data workloads. A vulnerability in the system's workflow enforcement could allow a logged-in user to perform actions they are not authorized to take. This could lead to unauthorized modifications of data or system configurations, potentially compromising the integrity of business intelligence operations.

Technical details

IBM watsonx.data intelligence versions 5.2.0 through 5.3.0 are vulnerable to improper enforcement of behavioral workflow (CWE-841). An authenticated attacker with low privileges can exploit this vulnerability over the network to bypass intended business logic or state transitions. By manipulating the sequence of operations or bypassing specific workflow steps, the attacker can perform unauthorized actions that should be restricted by the application's logic. The vulnerability has been addressed in version 5.3.1.

Affected products

  • IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: advisory
  • 2026-06-30: patched: Fixed in version 5.3.1

References

Related threats