TLS Certificate Validation Flaw in IBM Integrated Analytics System
CVE-2025-36290

5.9MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
28 August 2026

What is CVE-2025-36290?

The IBM Integrated Analytics System versions 1.0.0.0 through 1.0.31.0 suffers from a vulnerability related to TLS certificate validation. This oversight allows attackers to exploit improper validations or lack of validation, potentially leading to man-in-the-middle attacks. Such an exploit could enable malicious actors to intercept and extract sensitive information transmitted between the client and server, compromising data integrity and privacy. It is crucial for users to update to patched versions to mitigate risks associated with this vulnerability.

Affected Version(s)

Integrated Analytics System 1.0.0.0 <= 1.0.31.0

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.