Description
IBM Integrated Analytics System 1.0.0.0 through 1.0.31.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
Published: 2026-08-28
Score: 5.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM Integrated Analytics System versions 1.0.0.0 through 1.0.31.0 incorporate a cryptographic weakness in the Magneto component that relies on a predictable salt and weaker algorithms. The flaw enables an attacker who can access the cryptographic functions to recover encrypted data, breaking the confidentiality of stored or transmitted information. The weakness is classified as CWE‑759, which covers deficiencies in cryptographic hash or function implementations.

Affected Systems

The affected systems are IBM Integrated Analytics System releases 1.0.0.0 up to 1.0.31.0. The cryptographic issue resides in the Magneto component, and the vendor released a fix in version 1.0.32.0‑IM‑IIAS‑fp402 that replaces the vulnerable implementation.

Risk and Exploitability

The CVSS score of 5.9 indicates moderate severity. EPSS is not available, so the likelihood of exploitation cannot be quantified, and the vulnerability is not listed in CISA KEV. The CVE description does not specify an attack vector; it only states that the weakness could allow decryption if an attacker can interact with the cryptographic functions. The absence of explicit exploitation data suggests that this vulnerability is lower priority than remote code execution flaws, but remediation is nevertheless recommended to protect sensitive data.

Generated by OpenCVE AI on August 28, 2026 at 23:48 UTC.

Remediation

Vendor Solution

Affected Product(s)VRMFRemediation/FixesIBM Integrated Analytics System1.0.32.0 1.0.32.0-IM-IIAS-fp402 https://www.ibm.com/support/fixcentral/swg/selectFixes


OpenCVE Recommended Actions

  • Apply the IBM‑supplied fix for Integrated Analytics System 1.0.32.0‑IM‑IIAS‑fp402, which replaces the vulnerable Magneto cryptographic implementation.
  • If a patch cannot be applied immediately, replace the weak cryptographic routines with a stronger hash algorithm such as SHA‑256 and employ a randomly generated, high‑entropy salt rather than a predictable value.
  • Limit access to encryption and decryption functions and audit activities that involve handling encrypted data to reduce the risk of exploitation.

Generated by OpenCVE AI on August 28, 2026 at 23:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Description IBM Integrated Analytics System 1.0.0.0 through 1.0.31.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
Title IBM Integrated Analytics System (IIAS) is affected by a predictable salt vulnerability in Magneto component
First Time appeared Ibm
Ibm integrated Analytics System
Weaknesses CWE-759
CPEs cpe:2.3:a:ibm:integrated_analytics_system:1.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:integrated_analytics_system:1.0.31.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm integrated Analytics System
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Ibm Integrated Analytics System
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-28T20:41:58.142Z

Reserved: 2025-04-15T21:16:46.800Z

Link: CVE-2025-36271

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-28T22:16:45.587

Modified: 2026-08-28T22:16:45.587

Link: CVE-2025-36271

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-29T00:00:15Z

Weaknesses
  • CWE-759

    Use of a One-Way Hash without a Salt