VYPR

Cloud Pak For Data

by IBM

CVEs (20)

  • CVE-2023-42005HigMay 29, 2024
    risk 0.48cvss 7.4epss 0.00

    IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data 3.5, 4.0, 4.5, 4.6, 4.7, and 4.8 could allow a user with access to the Kubernetes pod, to make system calls compromising the security of containers. IBM X-Force ID: 265264.

  • CVE-2022-36769HigApr 26, 2023
    risk 0.47cvss 7.2epss 0.01

    IBM Cloud Pak for Data 4.5 and 4.6 could allow a privileged user to upload malicious files of dangerous types that can be automatically processed within the product's environment. IBM X-Force ID: 232034.

  • CVE-2023-28958HigJul 10, 2023
    risk 0.46cvss 7.0epss 0.01

    IBM Watson Knowledge Catalog on Cloud Pak for Data 4.0 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 251782.

  • CVE-2025-13616MedMar 3, 2026
    risk 0.42cvss 6.5epss 0.00

    IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 returns sensitive information in an HTTP response that could be used in further attacks against the system.

  • CVE-2023-26023MedJul 19, 2023
    risk 0.42cvss 6.5epss 0.01

    Planning Analytics Cartridge for Cloud Pak for Data 4.0 exposes sensitive information in logs which could lead an attacker to exploit this vulnerability to conduct further attacks. IBM X-Force ID: 247896.

  • CVE-2023-28955MedJul 10, 2023
    risk 0.42cvss 6.5epss 0.01

    IBM Watson Knowledge Catalog on Cloud Pak for Data 4.0 could allow an authenticated user send a specially crafted request that could cause a denial of service. IBM X-Force ID: 251704.

  • CVE-2022-22353MedMar 14, 2022
    risk 0.42cvss 6.5epss 0.01

    IBM Big SQL on IBM Cloud Pak for Data 7.1.0, 7.1.1, 7.2.0, and 7.2.3 could allow an authenticated user with appropriate permissions to obtain sensitive information by bypassing data masking rules using a CREATE TABLE SELECT statement. IBM X-Force ID: 220480.

  • CVE-2021-20486MedMay 26, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM Cloud Pak for Data 3.0 could allow an authenticated user to obtain sensitive information when installed with additional plugins. IBM X-Force ID: 197668.

  • CVE-2025-0719MedFeb 26, 2025
    risk 0.40cvss 6.1epss 0.00

    IBM Cloud Pak for Data 4.0.0 through 4.8.5 and 5.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials…

  • CVE-2023-38276MedOct 22, 2023
    risk 0.38cvss 5.9epss 0.00

    IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 exposes sensitive information in environment variables which could aid in further attacks against the system. IBM X-Force ID: 260736.

  • CVE-2023-38275MedOct 22, 2023
    risk 0.38cvss 5.9epss 0.00

    IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 exposes sensitive information in container images which could lead to further attacks against the system. IBM X-Force ID: 260730.

  • CVE-2023-27540MedJul 10, 2023
    risk 0.38cvss 5.9epss 0.01

    IBM Watson CP4D Data Stores 4.6.0 does not properly allocate resources without limits or throttling which could allow a remote attacker with information specific to the system to cause a denial of service. IBM X-Force ID: 248924.

  • CVE-2023-38735MedOct 22, 2023
    risk 0.37cvss 5.7epss 0.01

    IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 could allow a remote attacker to bypass security restrictions, caused by a reverse tabnabbing flaw. An attacker could exploit this vulnerability and redirect a victim to a phishing site. IBM X-Force ID: 262482.

  • CVE-2023-27877MedJul 19, 2023
    risk 0.34cvss 5.3epss 0.01

    IBM Planning Analytics Cartridge for Cloud Pak for Data 4.0 connects to a CouchDB server. An attacker can exploit an insecure password policy to the CouchDB server and collect sensitive information from the database. IBM X-Force ID: 247905.

  • CVE-2023-26026MedJul 19, 2023
    risk 0.34cvss 5.3epss 0.01

    Planning Analytics Cartridge for Cloud Pak for Data 4.0 exposes sensitive information in logs which could lead an attacker to exploit this vulnerability to conduct further attacks. IBM X-Force ID: 247896.

  • CVE-2022-38714MedFeb 12, 2024
    risk 0.32cvss 4.9epss 0.01

    IBM DataStage on Cloud Pak for Data 4.0.6 to 4.5.2 stores sensitive credential information that can be read by a privileged user. IBM X-Force ID: 235060.

  • CVE-2021-38971MedMar 14, 2022
    risk 0.32cvss 4.9epss 0.01

    IBM Data Virtualization on Cloud Pak for Data 1.3.0, 1.4.1, 1.5.0, 1.7.1 and 1.7.3 could allow an authorized user to bypass data masking rules and obtain sensitve information. IBM X-Force ID: 212620.

  • CVE-2021-38899MedSep 20, 2021
    risk 0.29cvss 4.4epss 0.00

    IBM Cloud Pak for Data 2.5 could allow a local user with special privileges to obtain highly sensitive information. IBM X-Force ID: 209575.

  • CVE-2024-35160MedNov 23, 2024
    risk 0.28cvss 4.3epss 0.00

    IBM Watson Query on Cloud Pak for Data 1.8, 2.0, 2.1, 2.2 and IBM Db2 Big SQL on Cloud Pak for Data 7.3, 7.4, 7.5, and 7.6 could allow an authenticated user to obtain sensitive information due to insufficient session expiration.

  • CVE-2023-27545MedFeb 29, 2024
    risk 0.26cvss 4.0epss 0.00

    IBM Watson CloudPak for Data Data Stores information disclosure 4.6.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 248947.