CVE-2025-36183 PUBLISHED

Privileged User File Upload Vulnerability Leading to Limited Server-Side Execution affects watsonx.data

Assigner: ibm
Reserved: 15.04.2025 Published: 17.02.2026 Updated: 17.02.2026

IBM watsonx.data 2.2 through 2.2.1 IBM Lakehouse could allow a privileged user to upload malicious files that could be executed server to modify limited files or data.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L
CVSS Score: 3.8

Product Status

Vendor IBM
Product watsonx.data
Versions
  • affected from 2.2 to 2.2.1 (incl.)

Solutions

The product needs to be installed or upgraded to the latest available level watsonx.data 2.2.2 or watsonx.data on CPD 5.2.2.  Installation/upgrade instructions can be found here: https://www.ibm.com/docs/en/watsonx/watsonxdata/5.2.x?topic=deployment-installing .

References

Problem Types

  • CWE-434 Unrestricted Upload of File with Dangerous Type CWE