PT-2025-7405 · Ibm · Ibm Watson Query On Cloud Pak For Data

Published

2025-02-21

·

Updated

2025-02-22

·

CVE-2024-22341

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Watson Query on Cloud Pak for Data versions 4.0.0 through 4.0.9 IBM Watson Query on Cloud Pak for Data versions 4.5.0 through 4.5.3 IBM Watson Query on Cloud Pak for Data versions 4.6.0 through 4.6.6 IBM Watson Query on Cloud Pak for Data versions 4.7.0 through 4.7.4 IBM Watson Query on Cloud Pak for Data versions 4.8.0 through 4.8.7
Description The issue is related to improper privilege management, which could allow unauthorized data access from a remote data source object. This is due to a privilege escalation issue.
Recommendations For versions 4.0.0 through 4.0.9, update to a version outside of this range to resolve the issue. For versions 4.5.0 through 4.5.3, update to a version outside of this range to resolve the issue. For versions 4.6.0 through 4.6.6, update to a version outside of this range to resolve the issue. For versions 4.7.0 through 4.7.4, update to a version outside of this range to resolve the issue. For versions 4.8.0 through 4.8.7, update to a version outside of this range to resolve the issue. As a temporary workaround, consider restricting access to remote data source objects to minimize the risk of unauthorized data access.

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-06821
CVE-2024-22341

Affected Products

Ibm Watson Query On Cloud Pak For Data