← Vulnerability feed

Vulnerability record · CVE-2025-14753 · published 18 September 2026

CVE-2025-14753: Ibm cloud pak for data path traversal vulnerability

Ibm · Cloud Pak For Data

IBM Cloud Pak for Data 5.1.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.

7.5 CVSS 3.1 High EPSS 0.46% · top 62.5% CWE-22 · Path traversal
7.5CVSS 3.1 base score
0.46%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
22 Sep 2026Last modified by NVD

Description

IBM Cloud Pak for Data 5.1.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://www.ibm.com/support/pages/node/7287141 PatchVendor Advisory

Track CVE-2025-14753 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2025-14754Ibm cloud pak for data os command injection vulnerabilityIBM Cloud Pak for Data 5.1.2 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper v…EPSS 0.44%7.5CVE-2023-26023Ibm cloud pak for data sensitive information in log file vulnerabilityPlanning Analytics Cartridge for Cloud Pak for Data 4.0 exposes sensitive information in logs which could lead an attacker to exploit this vulnerabil…EPSS 0.66%7.5CVE-2023-26026Ibm cloud pak for data information exposure vulnerabilityPlanning Analytics Cartridge for Cloud Pak for Data 4.0 exposes sensitive information in logs which could lead an attacker to exploit this vulnerabil…EPSS 0.57%7.5CVE-2023-27877Ibm cloud pak for data information exposure vulnerabilityIBM Planning Analytics Cartridge for Cloud Pak for Data 4.0 connects to a CouchDB server. An attacker can exploit an insecure password policy to the …EPSS 0.54%7.5CVE-2023-27540Ibm cloud pak for data allocation without limits vulnerabilityIBM Watson CP4D Data Stores 4.6.0 does not properly allocate resources without limits or throttling which could allow a remote attacker with informat…EPSS 1.3%7.2CVE-2022-36769Ibm cloud pak for data command injection vulnerabilityIBM Cloud Pak for Data 4.5 and 4.6 could allow a privileged user to upload malicious files of dangerous types that can be automatically processed wit…EPSS 0.87%6.5CVE-2021-20486Ibm cloud pak for data vulnerabilityIBM Cloud Pak for Data 3.0 could allow an authenticated user to obtain sensitive information when installed with additional plugins. IBM X-Force ID: …EPSS 0.85%6.1CVE-2025-0719Ibm cloud pak for data cross-site scripting vulnerabilityIBM Cloud Pak for Data 4.0.0 through 4.8.5 and 5.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to …EPSS 0.33%

Source: NIST National Vulnerability Database (record CVE-2025-14753), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.