IBM watsonx.data 2.2 through 2.2.1 IBM Lakehouse could allow a privileged user to upload malicious files that could be executed server to modify limited files or data.

Project Subscriptions

Vendors Products
Watsonxdata Subscribe
Advisories

No advisories yet.

Fixes

Solution

The product needs to be installed or upgraded to the latest available level watsonx.data 2.2.2 or watsonx.data on CPD 5.2.2.  Installation/upgrade instructions can be found here: https://www.ibm.com/docs/en/watsonx/watsonxdata/5.2.x?topic=deployment-installing .


Workaround

No workaround given by the vendor.

History

Tue, 17 Feb 2026 22:00:00 +0000

Type Values Removed Values Added
Description IBM watsonx.data 2.2 through 2.2.1 IBM Lakehouse could allow a privileged user to upload malicious files that could be executed server to modify limited files or data.
Title Privileged User File Upload Vulnerability Leading to Limited Server-Side Execution affects watsonx.data
First Time appeared Ibm
Ibm watsonxdata
Weaknesses CWE-434
CPEs cpe:2.3:a:ibm:watsonxdata:2.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:watsonxdata:2.2.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:watsonxdata:2.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm watsonxdata
References
Metrics cvssV3_1

{'score': 3.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-02-17T21:33:36.352Z

Reserved: 2025-04-15T21:16:23.419Z

Link: CVE-2025-36183

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-02-17T22:18:43.620

Modified: 2026-02-17T22:18:43.620

Link: CVE-2025-36183

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses