cbcvebase.

Ibm Watsonx.Data Intelligence vulnerabilities

11 known vulnerabilities affecting ibm/watsonx.data_intelligence.

Total CVEs
11
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM11

Vulnerabilities

Page 1 of 1
CVE-2025-36327P3MEDIUMCVSS 6.5v5.2.0, 5.2.1, 5.2.2, 5.3.02026-06-30
CVE-2025-36327 [MEDIUM] CWE-602 CVE-2025-36327: IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow an authenticated user to bypass IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow an authenticated user to bypass security controls and perform unauthorized actions due to client-side enforcement of sever-side security.
nvd
CVE-2025-36320P4MEDIUMCVSS 6.4v5.2.0, 5.2.1, 5.2.2, 5.3.02026-06-30
CVE-2025-36320 [MEDIUM] CWE-79 CVE-2025-36320: IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to stored cross-site scriptin IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2025-36336P4MEDIUMCVSS 5.9v5.2.0, 5.2.1, 5.2.2, 5.3.02026-06-30
CVE-2025-36336 [MEDIUM] CWE-319 CVE-2025-36336: IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 transmits data in clear text that could all IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.
nvd
CVE-2025-12530P4MEDIUMCVSS 5.9v5.2.2, 5.3.0, 5.3.1, 5.3.12026-06-30
CVE-2025-12530 [MEDIUM] CWE-319 CVE-2025-12530: IBM watsonx.data intelligence 5.2.2, 5.3.0, 5.3.1, 5.3.1 through patch-1 transmits data in clear tex IBM watsonx.data intelligence 5.2.2, 5.3.0, 5.3.1, 5.3.1 through patch-1 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.
nvd
CVE-2025-36321P4MEDIUMCVSS 5.7v5.2.0, 5.2.1, 5.2.2, 5.3.02026-06-30
CVE-2025-36321 [MEDIUM] CWE-80 CVE-2025-36321: IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to HTML injection. A remote a IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
nvd
CVE-2025-36323P4MEDIUMCVSS 5.4v5.2.0, 5.2.1, 5.2.2, 5.3.02026-06-30
CVE-2025-36323 [MEDIUM] CWE-79 CVE-2025-36323: IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to cross-site scripting. This IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2025-36335P4MEDIUMCVSS 5.5≥ 5.2.0, 5.2.1, 5.3.0, 5.3.1, ≤ 1.8.42026-04-30
CVE-2025-36335 [MEDIUM] CWE-256 CVE-2025-36335: IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.3.0, 5.3.1 stores user credentials in plain text which IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.3.0, 5.3.1 stores user credentials in plain text which can be read by a local user.
nvd
CVE-2025-36324P4MEDIUMCVSS 4.3v5.2.0, 5.2.1, 5.2.2, 5.3.02026-06-30
CVE-2025-36324 [MEDIUM] CWE-918 CVE-2025-36324: IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 s vulnerable to server-side request forgery IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 s vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
nvd
CVE-2025-36319P4MEDIUMCVSS 4.3v5.2.0, 5.2.1, 5.2.2, 5.3.02026-06-30
CVE-2025-36319 [MEDIUM] CWE-770 CVE-2025-36319: IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow an authenticated user to cause IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow an authenticated user to cause a temporary denial using a specially crafted HTTP request due to improper allocation of resource throttling.
nvd
CVE-2025-36333P4MEDIUMCVSS 4.3v5.2.0, 5.2.1, 5.2.2, 5.3.02026-06-30
CVE-2025-36333 [MEDIUM] CWE-841 CVE-2025-36333: IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow an authenticated user to perfor IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow an authenticated user to perform unauthorized actions due to the improper enforcement of behavioral workflow.
nvd
CVE-2025-36328P4MEDIUMCVSS 4.3v5.2.0, 5.2.1, 5.2.2, 5.3.02026-06-30
CVE-2025-36328 [MEDIUM] CWE-209 CVE-2025-36328: IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow a remote attacker to obtain sen IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
nvd
Ibm Watsonx.Data Intelligence vulnerabilities | cvebase