Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
The product needs to be installed or upgraded to the latest available level watsonx.data 2.2.1 or watsonx.data on CPD 5.2.1 Installation/upgrade instructions can be found here: https://www.ibm.com/docs/en/watsonx/watsonxdata/2.2.x?topic=deployment-installing https://www.ibm.com/docs/en/software-hub/5.2.x .
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-29868 | IBM Lakehouse (watsonx.data 2.2) could allow an authenticated user to obtain sensitive server component version information which could aid in further attacks against the system. |
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7245384 |
|
Fri, 19 Sep 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 18 Sep 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Lakehouse (watsonx.data 2.2) could allow an authenticated user to obtain sensitive server component version information which could aid in further attacks against the system. | |
| Title | IBM watsonx.data information disclosure | |
| First Time appeared |
Ibm
Ibm watsonx.data |
|
| Weaknesses | CWE-497 | |
| CPEs | cpe:2.3:a:ibm:watsonx.data:2.2:*:*:*:*:*:*:* | |
| Vendors & Products |
Ibm
Ibm watsonx.data |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-09-19T17:09:17.223Z
Reserved: 2025-04-15T21:16:19.940Z
Link: CVE-2025-36146
Updated: 2025-09-19T17:00:38.488Z
Status : Analyzed
Published: 2025-09-18T16:15:50.663
Modified: 2025-09-25T15:52:20.303
Link: CVE-2025-36146
No data.
OpenCVE Enrichment
No data.
EUVD