Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
The product needs to be installed or upgraded to the latest available level watsonx.data 2.1 or watsonx.data on CPD 5.1. Installation/upgrade instructions can be found here https://www.ibm.com/docs/en/software-hub/5.1.x?topic=watsonxdata-installing.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-31397 | IBM Lakehouse (watsonx.data 2.2) stores potentially sensitive information in log files that could be read by a local user. |
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7246267 |
|
Fri, 03 Oct 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:ibm:watsonx.data:2.2.0:*:*:*:*:*:*:* |
Mon, 29 Sep 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 27 Sep 2025 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Lakehouse (watsonx.data 2.2) stores potentially sensitive information in log files that could be read by a local user. | |
| Title | IBM watsonx.data information disclosure | |
| First Time appeared |
Ibm
Ibm watsonx.data |
|
| Weaknesses | CWE-532 | |
| CPEs | cpe:2.3:a:ibm:watsonx.data:2.2:*:*:*:*:*:*:* | |
| Vendors & Products |
Ibm
Ibm watsonx.data |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-09-29T14:04:30.872Z
Reserved: 2025-04-15T21:16:19.940Z
Link: CVE-2025-36144
Updated: 2025-09-29T14:04:23.376Z
Status : Analyzed
Published: 2025-09-27T01:15:42.927
Modified: 2025-10-03T19:15:18.317
Link: CVE-2025-36144
No data.
OpenCVE Enrichment
No data.
EUVD