Watsonx.Data
Vendor:
First CVE: Sep 18, 2025 · Active for under a year
9
Total CVEs
More Total CVEs than 86% of tracked products
4.5
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
5.6
Avg CVSS
Higher Avg CVSS than 16% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Watsonx.Data over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 18, 2025
10 months ago
Most Recent CVE
May 26, 2026
59 days ago
CVE Severity & Scoring
Watsonx.Data9 CVEs
11%
67%
22%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local2 (22.2%)
Network7 (77.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (88.9%)
Unknown0 (0.0%)
Required1 (11.1%)
Privileges Required
Low4 (44.4%)
High3 (33.3%)
None2 (22.2%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-36180HIGH IBM watsonx.data 2.2 through 2.3 IBM Lakehouse does not properly restrict communication between pods which could allow an attacker to transfer data between pods without restriction | Apr 30, 2026 | 7.5 | 29 | NO | NO |
CVE-2025-36335MEDIUM IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.3.0, 5.3.1 stores user credentials in plain text which can be read by a local user. | Apr 30, 2026 | 6.2 | 26 | NO | NO |
CVE-2025-36143HIGH IBM Lakehouse (watsonx.data 2.2) could allow an authenticated privileged user to execute arbitrary commands on the system due to improper validation of user supplied input. | Sep 18, 2025 | 7.2 | 24 | NO | NO |
CVE-2025-36140MEDIUM IBM watsonx.data 2.2 through 2.2.1 could allow an authenticated user to cause a denial of service through ingestion pods due to improper allocation of resources without limits. | Dec 8, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-36145MEDIUM IBM watsonx.data 2.2 through 2.3.1 IBM Lakehouse does not properly restrict inbound and outbound connections which could allow an attacker to transfer or modify files without restr | May 26, 2026 | 5.4 | 21 | NO | NO |
CVE-2025-36144MEDIUM IBM Lakehouse (watsonx.data 2.2) stores potentially sensitive information in log files that could be read by a local user. | Sep 27, 2025 | 5.5 | 20 | NO | NO |
CVE-2025-36146MEDIUM IBM Lakehouse (watsonx.data 2.2) could allow an authenticated user to obtain sensitive server component version information which could aid in further attacks against the system. | Sep 18, 2025 | 4.3 | 18 | NO | NO |
CVE-2025-36139MEDIUM IBM Lakehouse (watsonx.data 2.2) is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus alt | Sep 18, 2025 | 4.8 | 18 | NO | NO |
IBM watsonx.data 2.2 through 2.2.1 IBM Lakehouse could allow a privileged user to upload malicious files that could be executed server to modify limited files or data. | Feb 17, 2026 | 2.7 | 15 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Watsonx.Data
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.3.1 | 1 | 6.2 | 0.1% | 0 | 0 |
| 5.3.0 | 1 | 6.2 | 0.1% | 0 | 0 |
| 5.2.1 | 1 | 6.2 | 0.1% | 0 | 0 |
| 5.2.0 | 1 | 6.2 | 0.1% | 0 | 0 |
| 2.2.0 | 1 | 5.5 | 0.1% | 0 | 0 |
| 2.2 | 3 | 5.4 | 0.2% | 0 | 0 |