Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
The product needs to be installed or upgraded to the latest available level watsonx.data 2.2.1 or watsonx.data on CPD 5.2.1 Installation/upgrade instructions can be found here: https://www.ibm.com/docs/en/watsonx/watsonxdata/2.2.x?topic=deployment-installing https://www.ibm.com/docs/en/software-hub/5.2.x .
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-29862 | IBM Lakehouse (watsonx.data 2.2) could allow an authenticated privileged user to execute arbitrary commands on the system due to improper validation of user supplied input. |
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7245379 |
|
Fri, 19 Sep 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 18 Sep 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Lakehouse (watsonx.data 2.2) could allow an authenticated privileged user to execute arbitrary commands on the system due to improper validation of user supplied input. | |
| Title | IBM watsonx.data command execution | |
| First Time appeared |
Ibm
Ibm watsonx.data |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:a:ibm:watsonx.data:2.2:*:*:*:*:*:*:* | |
| Vendors & Products |
Ibm
Ibm watsonx.data |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-09-19T17:09:23.671Z
Reserved: 2025-04-15T21:16:19.940Z
Link: CVE-2025-36143
Updated: 2025-09-19T17:00:47.800Z
Status : Analyzed
Published: 2025-09-18T16:15:50.493
Modified: 2025-09-25T15:50:10.570
Link: CVE-2025-36143
No data.
OpenCVE Enrichment
No data.
EUVD