CVE-2025-36221
Description
IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System uses default passwords default passwords from the manufacturing process for use during the installation process, which could allow an attacker to bypass authentication.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
IBM Cloud Pak for Data System - Cyclops uses default manufacturing passwords during installation, allowing unauthenticated attackers to bypass authentication.
Vulnerability
IBM Cloud Pak for Data System - Cyclops versions 11.3.0.2 through 11.3.0.2 Interim Fix 002 use default passwords from the manufacturing process during installation. This allows an attacker to bypass authentication without any special configuration or conditions. The affected product is IBM Cloud Pak for Data System - Cyclops 11.3.0.2-IF2 and earlier [1].
Exploitation
An attacker with network access to the system can exploit the default credentials without requiring any authentication, privileges, or user interaction. The attacker simply uses the known default passwords to gain unauthorized access to the system [1].
Impact
Successful exploitation allows the attacker to bypass authentication, potentially gaining access to the system with the privileges of the default account. The CVSS v3.1 vector indicates low impact to integrity (C:N/I:L/A:N), meaning the attacker may be able to modify some data but not access confidential information or cause denial of service [1].
Mitigation
IBM has addressed this vulnerability in version 11.3.1.1. Users should upgrade to this fixed version. No workarounds are available. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog as of the publication date [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: >= 11.3.0.2, <= Interim Fix 002
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.