VYPR
Medium severity5.3NVD Advisory· Published May 26, 2026· Updated May 26, 2026

CVE-2025-36221

CVE-2025-36221

Description

IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System uses default passwords default passwords from the manufacturing process for use during the installation process, which could allow an attacker to bypass authentication.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

IBM Cloud Pak for Data System - Cyclops uses default manufacturing passwords during installation, allowing unauthenticated attackers to bypass authentication.

Vulnerability

IBM Cloud Pak for Data System - Cyclops versions 11.3.0.2 through 11.3.0.2 Interim Fix 002 use default passwords from the manufacturing process during installation. This allows an attacker to bypass authentication without any special configuration or conditions. The affected product is IBM Cloud Pak for Data System - Cyclops 11.3.0.2-IF2 and earlier [1].

Exploitation

An attacker with network access to the system can exploit the default credentials without requiring any authentication, privileges, or user interaction. The attacker simply uses the known default passwords to gain unauthorized access to the system [1].

Impact

Successful exploitation allows the attacker to bypass authentication, potentially gaining access to the system with the privileges of the default account. The CVSS v3.1 vector indicates low impact to integrity (C:N/I:L/A:N), meaning the attacker may be able to modify some data but not access confidential information or cause denial of service [1].

Mitigation

IBM has addressed this vulnerability in version 11.3.1.1. Users should upgrade to this fixed version. No workarounds are available. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog as of the publication date [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.