← Vulnerability feed

Vulnerability record · CVE-2025-36180 · published 30 April 2026

CVE-2025-36180: Ibm watsonx.data vulnerability

Ibm · Watsonx.Data

IBM watsonx.data 2.2 through 2.3 IBM Lakehouse does not properly restrict communication between pods which could allow an attacker to transfer data between pods without restrictions.

7.5 CVSS 3.1 High EPSS 0.19% · top 92.6% CWE-923 · CWE-923
7.5CVSS 3.1 base score
0.19%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

IBM watsonx.data 2.2 through 2.3 IBM Lakehouse does not properly restrict communication between pods which could allow an attacker to transfer data between pods without restrictions.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-36180 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.2CVE-2025-36143Ibm watsonx.data os command injection vulnerabilityIBM Lakehouse (watsonx.data 2.2) could allow an authenticated privileged user to execute arbitrary commands on the system due to improper validation …EPSS 0.34%6.5CVE-2025-36140Ibm watsonx.data allocation without limits vulnerabilityIBM watsonx.data 2.2 through 2.2.1 could allow an authenticated user to cause a denial of service through ingestion pods due to improper allocation o…EPSS 0.29%5.5CVE-2025-36335Ibm watsonx.data vulnerabilityIBM watsonx.data intelligence 5.2.0, 5.2.1, 5.3.0, 5.3.1 stores user credentials in plain text which can be read by a local user.EPSS 0.09%5.5CVE-2025-36144Ibm watsonx.data sensitive information in log file vulnerabilityIBM Lakehouse (watsonx.data 2.2) stores potentially sensitive information in log files that could be read by a local user.EPSS 0.12%5.3CVE-2025-36145Ibm watsonx.data vulnerabilityIBM watsonx.data 2.2 through 2.3.1 IBM Lakehouse does not properly restrict inbound and outbound connections which could allow an attacker to transfe…EPSS 0.17%4.8CVE-2025-36139Ibm watsonx.data cross-site scripting vulnerabilityIBM Lakehouse (watsonx.data 2.2) is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScr…EPSS 0.19%4.3CVE-2025-36146Ibm watsonx.data vulnerabilityIBM Lakehouse (watsonx.data 2.2) could allow an authenticated user to obtain sensitive server component version information which could aid in furthe…EPSS 0.23%2.7CVE-2025-36183Ibm watsonx.data unrestricted file upload vulnerabilityIBM watsonx.data 2.2 through 2.2.1 IBM Lakehouse could allow a privileged user to upload malicious files that could be executed server to modify limi…EPSS 0.19%

Source: NIST National Vulnerability Database (record CVE-2025-36180), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.