CVE-2025-36180

MEDIUM

Inadequate Pod Communication Restrictions, affects watsonx.data

Title source: cna
STIX 2.1

Description

IBM watsonx.data 2.2 through 2.3 IBM Lakehouse does not properly restrict communication between pods which could allow an attacker to transfer data between pods without restrictions.

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory patch
https://www.ibm.com/support/pages/node/7270593

Scores

CVSS v3 5.3
EPSS 0.0004
EPSS Percentile 13.7%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-923
Status published
Products (2)
ibm/watsonx.data 2.2.0 - 2.3
IBM/watsonx.data 2.2.0 - 2.3.0
Published Apr 30, 2026
Tracked Since May 01, 2026