Junglewise Threat Intelligence

CVE-2025-36335: IBM watsonx.data intelligence plaintext credential storage

CVE-2025-36335 · Severity: medium · CVSS 6.2 · Published 2026-04-30

Technologies: IBM Watsonx.Data Intelligence, IBM Watsonx.Data. Vendors: IBM.

Executive brief

IBM watsonx.data intelligence is a platform used for managing and analyzing large-scale data workloads. A security vulnerability in certain versions allows user credentials to be stored in plain text on the system. This could allow an individual with local access to the system to read sensitive login information, potentially leading to unauthorized account access and data exposure.

Technical details

IBM watsonx.data intelligence (versions 5.2.0, 5.2.1, 5.3.0, and 5.3.1) is vulnerable to plaintext storage of passwords (CWE-256). The application stores user credentials without encryption or hashing, making them accessible to any user with local access to the underlying file system or environment where the credentials are persisted. An attacker with local access can retrieve these credentials to escalate privileges or compromise user accounts. IBM recommends updating to fixed versions as outlined in their security bulletins.

Affected products

  • IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.3.0, 5.3.1

Timeline

  • 2026-04-30: disclosed
  • 2026-04-30: advisory

References

Related threats