CVE-2025-36145
בינונית 5.3
תיאור (מקור, אנגלית)
IBM watsonx.data 2.2 through 2.3.1 IBM Lakehouse does not properly restrict inbound and outbound connections which could allow an attacker to transfer or modify files without restrictions.
מדדים
- CVSS 3.1
-
5.3 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-5/8/2026
- CWE
- CWE-923
מוצרים מושפעים
ibm: watsonx.data
קישורים
- https://www.ibm.com/support/pages/node/7272498 Vendor Advisory