Description
IBM Cloud Pak for Data System (Yosemite 1.0) 3.0.5.2 could allow a remote attacker to obtain sensitive information due to the use of weak or deprecated cryptographic protocols.
Published: 2026-09-14
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure
Action: Patch Immediately
AI Analysis

Impact

The vulnerability arises from the use of weak or deprecated cryptographic protocols in IBM Cloud Pak for Data System (Yosemite 1.0) version 3.0.5.2. It allows a remote attacker to obtain sensitive information, compromising the confidentiality of data processed by the system. The flaw is solely an information‑disclosure issue and does not provide code execution or privilege escalation.

Affected Systems

IBM Cloud Pak for Data System (Yosemite 1.0) version 3.0.5.2 is affected. The vendor recommends upgrading to the fixed release 3.0.5.3-WS-ICPDS-NRS-fp346929, which resolves the weak protocol usage. Only this specific version and its preceding patch level are impacted.

Risk and Exploitability

The CVSS score of 8.2 indicates high severity for confidentiality compromise. The EPSS score is < 1% and the vulnerability is not listed in CISA KEV, but this does not preclude its exploitation. A remote attacker with network or API access can exploit deprecated protocols such as TLS 1.0 or SSLv3 to eavesdrop or retrieve data when those protocols remain enabled. The issue is not limited by privilege and can affect any user with sufficient network access to the system.

Generated by OpenCVE AI on September 20, 2026 at 23:22 UTC.

Remediation

Vendor Solution

Fixed VersionRemediation/FixesIBM Cloud Pak for Data System (Yosemite 1.0)  3.0.5.3-WS-ICPDS-NRS-fp346929 https://www.ibm.com/support/fixcentral/swg/downloadFixes


OpenCVE Recommended Actions

  • Upgrade IBM Cloud Pak for Data System (Yosemite 1.0) to release 3.0.5.3-WS-ICPDS-NRS-fp346 protocols (0, TLS 1.1, SSLv3) and enforce only TLS 1.2 or TLS 1.3.
  • Monitor network traffic for anomalous connections or attempts to negotiate deprecated protocols.
  • Disable or remove unsupported cryptographic protocols such as TLS 1.0 and SSLv3 from system configuration.

Generated by OpenCVE AI on September 20, 2026 at 23:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM Cloud Pak for Data System (Yosemite 1.0) 3.0.5.2 could allow a remote attacker to obtain sensitive information due to the use of weak or deprecated cryptographic protocols.
Title Vulnerabilities exists in IBM Cloud Pak for Data System
First Time appeared Ibm
Ibm cloud Pak For Data System Yosemite 10
Weaknesses CWE-327
CPEs cpe:2.3:a:ibm:cloud_pak_for_data_system_yosemite_10:3.0.5.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm cloud Pak For Data System Yosemite 10
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Ibm Cloud Pak For Data System Yosemite 10
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-14T20:13:31.654Z

Reserved: 2026-07-25T20:22:03.990Z

Link: CVE-2026-17467

cve-icon Vulnrichment

Updated: 2026-09-14T20:13:22.904Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T20:16:42.007

Modified: 2026-09-16T19:22:22.797

Link: CVE-2026-17467

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T23:30:07Z

Weaknesses
  • CWE-327

    Use of a Broken or Risky Cryptographic Algorithm