Sensitive Information Exposure in IBM Engineering Systems Design Rhapsody
CVE-2025-33020

5.9MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
23 July 2025

What is CVE-2025-33020?

IBM Engineering Systems Design Rhapsody versions 9.0.2, 10.0, and 10.0.1 contain a vulnerability that allows the transmission of sensitive information without encryption. This flaw poses a significant risk, as it enables potential attackers to intercept and exploit confidential data during transmission, highlighting the importance of robust encryption measures in safeguarding sensitive information.

Affected Version(s)

Engineering Systems Design Rhapsody 9.0.2, 10.0, 10.0.1

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-33020 : Sensitive Information Exposure in IBM Engineering Systems Design Rhapsody