Executive brief
IBM Cloud Pak for Data System is a data management and analytics platform used by enterprises to store and process sensitive business information. This vulnerability allows a remote attacker to intercept and decrypt communications by exploiting weak or deprecated cryptographic protocols, potentially exposing sensitive data including databases, credentials, and analytics workloads without requiring authentication or user interaction.
Technical details
The vulnerability stems from the use of weak or deprecated cryptographic protocols (CWE-327: Use of a Broken or Risky Cryptographic Algorithm) in IBM Cloud Pak for Data System version 3.0.5.2. An unauthenticated remote attacker on a network can exploit this vulnerability with no user interaction required to obtain sensitive information. The attack vector is network-based with low complexity, allowing an attacker to decrypt or intercept protected data. High confidentiality impact and low integrity impact are possible. The vulnerability has been fixed in version 3.0.5.3, specifically the WS-ICPDS-NRS-fp346929 hotfix.
Affected products
- IBM Cloud Pak for Data System 3.0.5.2
Timeline
- 2026-09-07: disclosed
- 2026-09-07: patched: Fixed in version 3.0.5.3-WS-ICPDS-NRS-fp346929