PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-36180 IBM CVE debrief

IBM watsonx.data 2.2 through 2.3 IBM Lakehouse has a vulnerability that allows unauthorized data transfers between pods due to improper restriction of communication between pods. This issue has a CVSS score of 5.3 and is classified as MEDIUM severity. Defenders should assess exposure and verify pod communication restrictions. The vulnerability requires verification of pod communication restrictions and review of vendor advisories. Affected deployments should prioritize verifying and restricting pod communication.

Vendor
IBM
Product
watsonx.data
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-30
Original CVE updated
2026-09-30
Advisory published
2026-04-30
Advisory updated
2026-09-30

Who should care

Defenders responsible for IBM watsonx.data 2.2 and 2.3 deployments should assess exposure and verify pod communication restrictions. They should prioritize verifying and restricting pod communication and review vendor advisories. Affected operators, platform administrators, vulnerability management teams, and security teams should be aware of the potential unauthorized data transfers between pods.

Why it matters

Defenders should care about CVE-2025-36180 because it affects IBM watsonx.data 2.2 and 2.3 deployments, potentially allowing unauthorized data transfers between pods. The vulnerability requires verification of pod communication restrictions and review of vendor advisories.

  • Potential unauthorized data transfer between pods
  • Need to verify and restrict pod communication
  • Possible impact on data confidentiality
  • Requires review of vendor advisory and deployment configurations

Technical summary

IBM watsonx.data 2.2 through 2.3 IBM Lakehouse does not properly restrict communication between pods which could allow an attacker to transfer data between pods without restrictions. The vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity.

Defensive priority

Defenders should prioritize verifying and restricting pod communication in IBM watsonx.data 2.2 and 2.3 deployments.

Recommended defensive actions

  • Verify and restrict pod communication in IBM watsonx.data 2.2 and 2.3 deployments
  • Review and apply vendor advisory from IBM
  • Monitor for potential data transfers between pods

Evidence notes

The CVE record and NVD entry provide details on the vulnerability in IBM watsonx.data 2.2 through 2.3. Vendor advisory is available from IBM. Evidence is limited to public CVE and NVD information. Defenders should verify pod communication restrictions and review vendor advisories for affected deployments.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-36180 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-36180

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-36180 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-36180

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.