Impact
IBM Integrated Analytics System versions 1.0.0.0 through 1.0.31.0 incorporate a cryptographic weakness in the Magneto component that relies on a predictable salt and weaker algorithms. The flaw enables an attacker who can access the cryptographic functions to recover encrypted data, breaking the confidentiality of stored or transmitted information. The weakness is classified as CWE‑759, which covers deficiencies in cryptographic hash or function implementations.
Affected Systems
The affected systems are IBM Integrated Analytics System releases 1.0.0.0 up to 1.0.31.0. The cryptographic issue resides in the Magneto component, and the vendor released a fix in version 1.0.32.0‑IM‑IIAS‑fp402 that replaces the vulnerable implementation.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity. EPSS is not available, so the likelihood of exploitation cannot be quantified, and the vulnerability is not listed in CISA KEV. The CVE description does not specify an attack vector; it only states that the weakness could allow decryption if an attacker can interact with the cryptographic functions. The absence of explicit exploitation data suggests that this vulnerability is lower priority than remote code execution flaws, but remediation is nevertheless recommended to protect sensitive data.
OpenCVE Enrichment