Executive brief
IBM watsonx.data intelligence, a platform used for data management and AI analytics, is affected by a security flaw where sensitive information is transmitted without encryption. An attacker positioned on the same network could intercept this traffic to steal confidential data. This could lead to the exposure of business-critical information or credentials.
Technical details
IBM watsonx.data intelligence versions 5.2.0 through 5.3.0 are vulnerable to cleartext transmission of sensitive information (CWE-319). The application fails to encrypt data during transit, which can be exploited by a remote attacker using man-in-the-middle (MITM) techniques. While the attack requires the adversary to be positioned appropriately to intercept network traffic (High Attack Complexity), no authentication or user interaction is required to capture the data. IBM has addressed this vulnerability in Watson Data Intelligence version 5.3.1.
Affected products
- IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0
Timeline
- 2026-06-30: advisory: IBM published the security bulletin and NVD record.
- 2026-06-30: patched: Vulnerability addressed in version 5.3.1.