CVE-2025-36333
MEDIUMDescription
IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow an authenticated user to perform unauthorized actions due to the improper enforcement of behavioral workflow.
Is your site exposed to CVE-2025-36333?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
EPSS — Exploit Prediction
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| ibm | watsonx.data_intelligence |
| ibm | software_hub |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2025-36333? +
How severe is CVE-2025-36333? +
What products are affected by CVE-2025-36333? +
How do I check if I'm vulnerable to CVE-2025-36333? +
Related Vulnerabilities
User Enumeration and Data Integrity in Barcode functionality in OpenText Content Management versions 24.3-25.1on Windows and Linux allows a malicous …
WatchGuard Dimension provides a client-side lock/unlock UI control for management changes. The server-side configuration endpoint does not enforce this lock/unlock …
A business logic flaw in WatchGuard Dimension allows an authenticated administrator to trigger multiple backend operations within a single logical …
Our payment integration with Mollie did not properly validate payment status responses. An attacker could use a successful payment status …
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4, a …
Our payment integration with Oppwa-based payment methods did not properly validate payment status responses. An attacker could use a successful …