Description
IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System uses default passwords default passwords from the manufacturing process for use during the installation process, which could allow an attacker to bypass authentication.
Published: 2026-05-26
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM Cloud Pak for Data System – Cyclops versions 11.3.0.2 through Interim Fix 002 contain default installation passwords that are derived from the manufacturing process. The presence of these preset passwords allows an attacker who can reach the installation interface to authenticate without valid credentials, effectively bypassing normal authentication controls. This weakness enables an attacker to gain initial access and potentially elevate privileges to an administrator level, compromising the confidentiality, integrity, and availability of the system.

Affected Systems

The affected product is IBM Cloud Pak for Data System – Cyclops, specifically versions 11.3.0.2 up to Interim Fix 002. Any deployment using those releases is vulnerable until upgraded to the patched release 11.3.1.1-WS-ICPDS-CYCLOPS-fp278500.

Risk and Exploitability

The CVSS score of 5.3 indicates a medium severity vulnerability. Because EPSS information is unavailable and the vulnerability is not listed in the CISA KEV catalog, the known exploitation probability is uncertain, but the ability to bypass authentication could be leveraged by an attacker who gains network access to the installation process. The attack vector is inferred to be remote, relying on exposure of the installation interface, as the description does not reference local privileges. Consequently, the risk merits prompt remediation while monitoring for any related exploit activity.

Generated by OpenCVE AI on May 26, 2026 at 18:26 UTC.

Remediation

Vendor Solution

Fixed versionFix linkIBM Cloud Pak for Data System - Cyclops 11.3.1.1-WS-ICPDS-CYCLOPS-fp278500 https://www.ibm.com/support/fixcentral/swg/downloadFixes


OpenCVE Recommended Actions

  • Upgrade Cyclops component to patched release 11.3.1.1-WS-ICPDS-CYCLOPS-fp278500 via IBM Fix Central or corresponding package manager.
  • After upgrade, verify that the default manufacturing passwords no longer exist and replace any remaining default credentials with strong, unique passwords.
  • Enable password policy enforcement and disable any remote installation password entry if possible to ensure no future default credentials can be used.

Generated by OpenCVE AI on May 26, 2026 at 18:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 26 May 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 26 May 2026 17:00:00 +0000

Type Values Removed Values Added
Description IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System uses default passwords default passwords from the manufacturing process for use during the installation process, which could allow an attacker to bypass authentication.
Title Vulnerabilities exists in IBM Cloud Pak for Data System (CPDS 1.0) - Cyclops.
First Time appeared Ibm
Ibm cloud Pak For Data System Cyclops
Weaknesses CWE-1392
CPEs cpe:2.3:a:ibm:cloud_pak_for_data_system___cyclops:11.3.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_data_system___cyclops:interim:interim_fix_002:*:*:*:*:*:*
Vendors & Products Ibm
Ibm cloud Pak For Data System Cyclops
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Ibm Cloud Pak For Data System Cyclops
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-05-26T17:48:22.026Z

Reserved: 2025-04-15T21:16:41.802Z

Link: CVE-2025-36221

cve-icon Vulnrichment

Updated: 2026-05-26T17:48:08.375Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-05-26T17:16:29.270

Modified: 2026-05-26T19:06:14.330

Link: CVE-2025-36221

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-26T18:30:12Z

Weaknesses