Cloud Pak For Data

Vendor:

First CVE: May 26, 2021 · Active for 5 years

15
Total CVEs
More Total CVEs than 92% of tracked products
2.5
Avg CVEs / Year
Higher CVE frequency than 74% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 32% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Cloud Pak For Data over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 26, 2021
5 years ago
Most Recent CVE
Jun 22, 2026
33 days ago

CVE Severity & Scoring

Cloud Pak For Data15 CVEs
All CVEs352,427 CVEs
MediumHigh
Attack Vector
Local2 (13.3%)
Network13 (86.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (93.3%)
High1 (6.7%)
Unknown0 (0.0%)
User Interaction
None14 (93.3%)
Unknown0 (0.0%)
Required1 (6.7%)
Privileges Required
Low6 (40.0%)
High4 (26.7%)
None5 (33.3%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8,5.0,5.1,5.2,5.3 could allow an authenticated user to cause a denial of service when creating new
Jun 22, 20266.528NONO
IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, 5.3 could allow a privileged user to perform operations and obtain sensitive info
Jun 22, 20266.527NONO
IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data 3.5, 4.0, 4.5, 4.6, 4.7, and 4.8 could allow a user with access to the Kubernetes pod, to make system calls co
May 29, 20248.824NONO
IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, and 5.3 could allow an authenticated user to bypass client-side validation and ma
Jun 22, 20265.323NONO
IBM Planning Analytics Cartridge for Cloud Pak for Data 4.0 connects to a CouchDB server. An attacker can exploit an insecure password policy to the CouchDB server and collect sens
Jul 19, 20237.523NONO
Planning Analytics Cartridge for Cloud Pak for Data 4.0 exposes sensitive information in logs which could lead an attacker to exploit this vulnerability to conduct further attacks.
Jul 19, 20237.523NONO
IBM Cloud Pak for Data 4.5 and 4.6 could allow a privileged user to upload malicious files of dangerous types that can be automatically processed within the product's environment.
Apr 26, 20237.223NONO
IBM Cloud Pak for Data 3.0 could allow an authenticated user to obtain sensitive information when installed with additional plugins. IBM X-Force ID: 197668.
May 26, 20216.522NONO
IBM Watson CP4D Data Stores 4.6.0 does not properly allocate resources without limits or throttling which could allow a remote attacker with information specific to the system to c
Jul 10, 20237.521NONO
IBM Big SQL on IBM Cloud Pak for Data 7.1.0, 7.1.1, 7.2.0, and 7.2.3 could allow an authenticated user with appropriate permissions to obtain sensitive information by bypassing dat
Mar 14, 20226.521NONO

Exploit Exposure

Signals from CVEs in this product scope (15 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (15 CVEs).

Media Mentions

Signals from CVEs in this product scope (15 CVEs).

Top CNAs Publishing CVEs For Cloud Pak For Data

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
5.016.10.3%00
4.6.026.50.8%00
4.617.20.9%00
4.517.20.9%00
4.037.50.6%00
3.016.50.9%00
2.514.40.3%00