Junglewise Threat Intelligence

CVE-2025-36336: IBM watsonx.data intelligence cleartext transmission of sensitive information

CVE-2025-36336 · Severity: medium · CVSS 5.9 · Published 2026-06-30

Technologies: IBM Watsonx.Data Intelligence. Vendors: IBM.

Executive brief

IBM watsonx.data intelligence, a platform used for data management and AI analytics, is affected by a security flaw where sensitive information is transmitted without encryption. An attacker positioned on the same network could intercept this traffic to steal confidential data. This could lead to the exposure of business-critical information or credentials.

Technical details

IBM watsonx.data intelligence versions 5.2.0 through 5.3.0 are vulnerable to cleartext transmission of sensitive information (CWE-319). The application fails to encrypt data during transit, which can be exploited by a remote attacker using man-in-the-middle (MITM) techniques. While the attack requires the adversary to be positioned appropriately to intercept network traffic (High Attack Complexity), no authentication or user interaction is required to capture the data. IBM has addressed this vulnerability in Watson Data Intelligence version 5.3.1.

Affected products

  • IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0

Timeline

  • 2026-06-30: advisory: IBM published the security bulletin and NVD record.
  • 2026-06-30: patched: Vulnerability addressed in version 5.3.1.

References

Related threats