Denial of Service Vulnerability in IBM WatsonX.data Product
CVE-2025-36140

6.5MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
8 December 2025

What is CVE-2025-36140?

IBM's WatsonX.data versions 2.2 and 2.2.1 are susceptible to a denial of service attack. This vulnerability arises from improper resource allocation, which can be exploited by authenticated users to overuse system resources, causing service interruptions. By manipulating ingestion pods without proper limits, attackers can lead to significant operational disruptions. It's crucial for users of affected versions to apply the necessary patches to mitigate this risk.

Affected Version(s)

watsonx.data 2.2 <= 2.2.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-36140 : Denial of Service Vulnerability in IBM WatsonX.data Product