IBM Watson Query Improper Privilege Management Vulnerability Allowing Unauthorized Data Access on Cloud Pak for Data

Vulnerability

A vulnerability exists in IBM Watson Query on Cloud Pak for Data versions 4.0.0 through 4.0.9, 4.5.0 through 4.5.3, 4.6.0 through 4.6.6, 4.7.0 through 4.7.4, and 4.8.0 through 4.8.7. This vulnerability could enable unauthorized data access from a remote data source object, stemming from inadequate privilege management.

Impact

Exploitation of this vulnerability could lead to unauthorized access to data from remote data source objects.

Remediation

Users are advised to upgrade to version 2.2.8 or later for IBM Watson Query on Cloud Pak for Data versions 4.6, 4.7, and 4.8. For those on Cloud Pak for Data version 4.5, an upgrade to version 2.1.3 is recommended before moving to version 2.2.8. Instructions for upgrading can be found in the IBM Cloud Pak for Data documentation.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.4
impact
2.5
exploitability
4.9
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.