Impact
The vulnerability arises from the use of weak or deprecated cryptographic protocols in IBM Cloud Pak for Data System (Yosemite 1.0) version 3.0.5.2. It allows a remote attacker to obtain sensitive information, compromising the confidentiality of data processed by the system. The flaw is solely an information‑disclosure issue and does not provide code execution or privilege escalation.
Affected Systems
IBM Cloud Pak for Data System (Yosemite 1.0) version 3.0.5.2 is affected. The vendor recommends upgrading to the fixed release 3.0.5.3-WS-ICPDS-NRS-fp346929, which resolves the weak protocol usage. Only this specific version and its preceding patch level are impacted.
Risk and Exploitability
The CVSS score of 8.2 indicates high severity for confidentiality compromise. The EPSS score is < 1% and the vulnerability is not listed in CISA KEV, but this does not preclude its exploitation. A remote attacker with network or API access can exploit deprecated protocols such as TLS 1.0 or SSLv3 to eavesdrop or retrieve data when those protocols remain enabled. The issue is not limited by privilege and can affect any user with sufficient network access to the system.
OpenCVE Enrichment