CVE-2025-36220
Description
IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
IBM Cloud Pak for Data System Cyclops 11.3.0.2-IF2 is vulnerable to SQL injection, allowing remote attackers to view, add, modify, or delete database information.
Vulnerability
IBM Cloud Pak for Data System Cyclops version 11.3.0.2-IF2 (and possibly earlier interim fixes) is vulnerable to SQL injection [1]. A remote attacker could send specially crafted SQL statements to the back-end database, exploiting improper neutralization of special elements (CWE-89) [1]. The CVSS v3 base score is 4.3 (Medium) with vector AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N [1].
Exploitation
The attacker needs network access to the affected system and low privileges (PR:L) [1]. No user interaction is required (UI:N) [1]. The attack complexity is low (AC:L) [1]. The attacker sends crafted SQL queries that bypass input sanitization, reaching the database directly [1].
Impact
On success, the attacker can view, add, modify, or delete information in the back-end database [1]. This results in limited integrity impact (I:L) and no confidentiality or availability impact (C:N, A:N) per the CVSS score [1].
Mitigation
IBM has published a security bulletin (reference [1]) stating the vulnerability is addressed in IBM Cloud Pak for Data System Cyclops 11.3.1.1. No workarounds are listed. Users should upgrade to the fixed version. If no upgrade is possible, restrict network access and monitor database queries for anomalous patterns.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: >=11.3.0.2 <11.3.0.2 Interim Fix 002
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.