Description
IBM Integrated Analytics System 1.0.0.0 through 1.0.31.0 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information using man in the middle techniques.
Published: 2026-08-28
Score: 5.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM Integrated Analytics System versions from 1.0.0.0 through 1.0.31.0 do not properly validate TLS certificates when establishing secure connections in the JWT service component. An attacker who can intercept network traffic between the component and its clients could present a forged certificate and decrypt or tamper with otherwise encrypted data, potentially exposing sensitive business information and credentials.

Affected Systems

The affected product is IBM Integrated Analytics System. All installations running versions 1.0.0.0 up to and including 1.0.31.0 are impacted. The official fix is available in version 1.0.32.0‑IM‑IIAS‑fp402.

Risk and Exploitability

The CVSS score is 5.9, indicating a moderate risk that allows an adversary to compromise data confidentiality. The EPSS score is not reported, so the exploitation probability is unknown. The vulnerability is not listed in the CISA KEV catalog, suggesting it has not been widely exploited. The likely attack vector is a network‑based man‑in‑the‑middle attack, where a remote attacker intercepts TLS traffic between the JWT service component and its clients or external servers. This inference follows from the description of improper certificate validation.

Generated by OpenCVE AI on August 28, 2026 at 23:28 UTC.

Remediation

Vendor Solution

Affected Product(s)VRMFRemediation/FixesIBM Integrated Analytics System1.0.32.0 1.0.32.0-IM-IIAS-fp402 https://www.ibm.com/support/fixcentral/swg/selectFixes


OpenCVE Recommended Actions

  • Apply the IBM‑supplied patch to upgrade to Integrated Analytics System 1.0.32.0‑IM‑IIAS‑fp402, which includes correct TLS certificate validation.
  • If the patch cannot be applied immediately, restrict network access to the JWT service component using firewalls or VLAN segmentation so that only known, trusted endpoints can connect.
  • Implement certificate pinning or additional verification of server certificates for all TLS connections to the JWT component to mitigate the risk of accepting forged certificates.

Generated by OpenCVE AI on August 28, 2026 at 23:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Description IBM Integrated Analytics System 1.0.0.0 through 1.0.31.0 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information using man in the middle techniques.
Title IBM Integrated Analytics System (IIAS) is affected by improper SSL/TLS certificate validation vulnerability in JWT service component
First Time appeared Ibm
Ibm integrated Analytics System
Weaknesses CWE-295
CPEs cpe:2.3:a:ibm:integrated_analytics_system:1.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:integrated_analytics_system:1.0.31.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm integrated Analytics System
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Ibm Integrated Analytics System
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-28T20:42:23.682Z

Reserved: 2025-04-15T21:16:48.649Z

Link: CVE-2025-36290

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-28T22:16:45.757

Modified: 2026-08-28T22:16:45.757

Link: CVE-2025-36290

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-29T00:30:16Z

Weaknesses
  • CWE-295

    Improper Certificate Validation