PatchSiren cyber security CVE debrief
CVE-2025-36180 IBM CVE debrief
IBM watsonx.data 2.2 through 2.3 IBM Lakehouse has a vulnerability that allows unauthorized data transfers between pods due to improper restriction of communication between pods. This issue has a CVSS score of 5.3 and is classified as MEDIUM severity. Defenders should assess exposure and verify pod communication restrictions. The vulnerability requires verification of pod communication restrictions and review of vendor advisories. Affected deployments should prioritize verifying and restricting pod communication.
- Vendor
- IBM
- Product
- watsonx.data
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-30
- Original CVE updated
- 2026-09-30
- Advisory published
- 2026-04-30
- Advisory updated
- 2026-09-30
Who should care
Defenders responsible for IBM watsonx.data 2.2 and 2.3 deployments should assess exposure and verify pod communication restrictions. They should prioritize verifying and restricting pod communication and review vendor advisories. Affected operators, platform administrators, vulnerability management teams, and security teams should be aware of the potential unauthorized data transfers between pods.
Why it matters
Defenders should care about CVE-2025-36180 because it affects IBM watsonx.data 2.2 and 2.3 deployments, potentially allowing unauthorized data transfers between pods. The vulnerability requires verification of pod communication restrictions and review of vendor advisories.
- Potential unauthorized data transfer between pods
- Need to verify and restrict pod communication
- Possible impact on data confidentiality
- Requires review of vendor advisory and deployment configurations
Technical summary
IBM watsonx.data 2.2 through 2.3 IBM Lakehouse does not properly restrict communication between pods which could allow an attacker to transfer data between pods without restrictions. The vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity.
Defensive priority
Defenders should prioritize verifying and restricting pod communication in IBM watsonx.data 2.2 and 2.3 deployments.
Recommended defensive actions
- Verify and restrict pod communication in IBM watsonx.data 2.2 and 2.3 deployments
- Review and apply vendor advisory from IBM
- Monitor for potential data transfers between pods
Evidence notes
The CVE record and NVD entry provide details on the vulnerability in IBM watsonx.data 2.2 through 2.3. Vendor advisory is available from IBM. Evidence is limited to public CVE and NVD information. Defenders should verify pod communication restrictions and review vendor advisories for affected deployments.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-36180 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-36180
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-36180 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-36180
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.ibm.com/support/pages/node/7270593
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.