CVE-2025-36319: IBM watsonx.data Intelligence DoS Vulnerability
IBM watsonx.data intelligence versions 5.2.0 through 5.3.0 contain a denial-of-service vulnerability accessible to authenticated users. An attacker with valid credentials can send a specially crafted HTTP request that exploits improper resource throttling controls, temporarily disrupting service availability. The vulnerability does not compromise confidentiality or integrity—only availability is at risk.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 4.3 MEDIUM · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
- Weaknesses (CWE)
- CWE-770
- Affected products
- 2 configuration(s)
- Published / Modified
- 2026-06-30 / 2026-07-06
NVD description (verbatim)
IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow an authenticated user to cause a temporary denial using a specially crafted HTTP request due to improper allocation of resource throttling.
1 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2025-36319 stems from insufficient resource allocation throttling in IBM watsonx.data intelligence. The affected versions fail to properly enforce limits on HTTP request processing, allowing an authenticated attacker to craft requests that consume disproportionate system resources. This violates CWE-770 (Allocation of Resources Without Limits or Throttling) principles. The CVSS 3.1 score of 4.3 reflects that while the attack requires prior authentication and produces only temporary service degradation, the network-accessible nature and low complexity of exploitation create meaningful operational risk.
Business impact
Organizations operating affected watsonx.data intelligence instances may experience temporary service interruptions initiated by authenticated users or compromised accounts. In data-intensive environments where watsonx.data serves analytics or machine-learning workflows, denial-of-service events could disrupt decision-making processes, delay data pipeline execution, and impact dependent applications. The threat is amplified if service accounts or broadly-scoped credentials are compromised, enabling a wider attack surface.
Affected systems
IBM watsonx.data intelligence versions 5.2.0, 5.2.1, 5.2.2, and 5.3.0 are confirmed vulnerable. Organizations using these releases should prioritize inventory verification. Verify your current version against IBM's product support portal. The vulnerability also affects IBM Software Hub instances that bundle or depend on watsonx.data intelligence—check your deployment model to confirm exposure.
Exploitability
This vulnerability requires valid authentication credentials to exploit, which meaningfully constrains the attack surface compared to unauthenticated flaws. However, the low attack complexity and network accessibility mean that insider threats, compromised service accounts, or credential stuffing against weak authentication mechanisms present realistic exploit scenarios. Public exploit code has not been reported, but the straightforward nature of crafting malicious HTTP requests suggests proof-of-concept development is within reach for determined actors.
Remediation
IBM has released patched versions addressing this flaw. Consult IBM's security advisories and release notes to identify the specific patched versions for your deployment model (cloud-hosted, on-premises, or containerized). Patching is the definitive remediation. Organizations unable to patch immediately should implement network-level access controls restricting HTTP traffic to watsonx.data intelligence and enforce strict authentication policies, credential rotation, and monitoring of service account activity.
Patch guidance
Apply the latest available patch version for your watsonx.data intelligence release line. IBM's security advisories will specify the patched version numbers—verify these directly with IBM support or your vendor portal rather than assuming versions beyond 5.3.0 are automatically safe. If your deployment is cloud-hosted via IBM Cloud, check for automatic patching policies. For on-premises deployments, schedule patching during a maintenance window to minimize disruption, and test in a staging environment first.
Detection guidance
Monitor HTTP access logs for watsonx.data intelligence for patterns consistent with resource exhaustion: unusually high request rates from a single authenticated user, requests with abnormal payload sizes or parameter combinations, or temporal clustering of requests that correlate with performance degradation events. Implement alerting on authentication failures followed by successful logins, which may indicate credential compromise preceding exploitation. Enable detailed audit logging in watsonx.data to capture authenticated session activity and correlate with system resource metrics (CPU, memory, thread pools).
Why prioritize this
Although the CVSS score of 4.3 places this in the MEDIUM range, prioritization depends on your risk posture. If watsonx.data intelligence is mission-critical for analytics or machine-learning operations, or if your authentication hygiene is weak (shared service accounts, infrequent credential rotation), treat this as a higher-priority fix. If the service is non-critical or air-gapped, lower priority is justified. The absence of KEV status indicates this is not actively exploited in the wild at publication, reducing urgency compared to actively-weaponized flaws.
Risk score, explained
The CVSS 3.1 score of 4.3 (MEDIUM severity) reflects: network-accessible attack vector, low attack complexity (straightforward HTTP request crafting), and requirement for low-privilege authentication. The impact is confined to availability (temporary denial)—no confidentiality or integrity loss is possible. The score appropriately conveys moderate but real operational risk, particularly in environments where service availability directly affects business processes. Context-specific factors (asset criticality, authentication controls, insider threat profile) should inform your internal risk rating.
Frequently asked questions
Do I need to patch immediately if our watsonx.data instance is on an internal network?
Network segmentation reduces but does not eliminate risk. An insider or compromised account from a connected system could still exploit the flaw. Patching remains the recommended action; if patching is delayed, strengthen authentication controls and implement detailed access logging.
Can this vulnerability be exploited without valid credentials?
No. The vulnerability explicitly requires prior authentication. Unauthenticated attackers cannot trigger the denial-of-service condition. This significantly narrows the attack surface compared to pre-authentication flaws, but insider threats and credential compromise remain plausible attack vectors.
What is the difference between this CVSS score and other vulnerabilities I'm tracking?
A CVSS 4.3 is lower than critical or high-severity flaws but still material. It reflects that the attack requires authentication and causes only temporary (not permanent) damage. Higher-severity vulnerabilities typically allow unauthenticated exploitation, result in data breaches, or enable remote code execution.
If we can't patch immediately, what else should we do?
Implement strict access controls: restrict network access to watsonx.data to known, trusted subnets; enforce multi-factor authentication for all user accounts; monitor and rotate service account credentials frequently; enable comprehensive audit logging; and set up alerts for unusual authentication or request patterns. These controls mitigate risk while patching is planned.
This analysis is provided for informational purposes. SEC.co makes no warranty regarding the accuracy or completeness of CVE data or vendor advisories. Organizations must independently verify patch availability, affected version status, and compatibility testing with IBM and applicable security advisories before deploying patches. This document does not constitute legal or compliance advice. Consult your security team and vendor documentation for authoritative remediation guidance. Source: NVD (public-domain), retrieved 2026-08-09. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2024-54178MEDIUMIBM Db2 Cloud Pak for Data Denial of Service via Resource Allocation Flaw
- CVE-2026-10533MEDIUMOpenShift ResourceQuota Bypass Leads to API Server DoS
- CVE-2026-10740MEDIUMs2n-quic Memory Allocation DoS – QUIC CRYPTO Frame Reassembler
- CVE-2026-12760MEDIUMTP-Link Tapo C200 v3 IPv4 Fragmentation DoS Vulnerability
- CVE-2026-14362MEDIUMHashiCorp Memberlist Denial of Service Vulnerability
- CVE-2026-1500MEDIUMGitLab Authenticated Denial of Service via Malicious File Upload
- CVE-2026-24720MEDIUMQNAP File Station 6 Resource Exhaustion Vulnerability
- CVE-2026-28237MEDIUMAMD uProf Resource Exhaustion Vulnerability – Patch Guidance