Impact
IBM Integrated Analytics System versions from 1.0.0.0 through 1.0.31.0 do not properly validate TLS certificates when establishing secure connections in the JWT service component. An attacker who can intercept network traffic between the component and its clients could present a forged certificate and decrypt or tamper with otherwise encrypted data, potentially exposing sensitive business information and credentials.
Affected Systems
The affected product is IBM Integrated Analytics System. All installations running versions 1.0.0.0 up to and including 1.0.31.0 are impacted. The official fix is available in version 1.0.32.0‑IM‑IIAS‑fp402.
Risk and Exploitability
The CVSS score is 5.9, indicating a moderate risk that allows an adversary to compromise data confidentiality. The EPSS score is not reported, so the exploitation probability is unknown. The vulnerability is not listed in the CISA KEV catalog, suggesting it has not been widely exploited. The likely attack vector is a network‑based man‑in‑the‑middle attack, where a remote attacker intercepts TLS traffic between the JWT service component and its clients or external servers. This inference follows from the description of improper certificate validation.
OpenCVE Enrichment