Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-37526


IBM Watson Query on Cloud Pak for Data (IBM Data Virtualization 1.8, 2.0, 2.1, 2.2, and 3.0.0) could allow an authenticated user to obtain sensitive information from objects published using Watson Query due to an improper data protection mechanism.


Published

2025-01-27T22:15:11.770

Last Modified

2025-08-18T18:07:27.443

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-497
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ibm data_virtualization_on_cloud_pak_for_data 1.8.0 Yes
Application ibm data_virtualization_on_cloud_pak_for_data 3.0.0 Yes
Application ibm data_virtualization_on_cloud_pak_for_data 4.5.0 Yes
Application ibm data_virtualization_on_cloud_pak_for_data 5.0.0 Yes
Application ibm watson_query_with_cloud_pak_for_data 2.0 Yes
Application ibm watson_query_with_cloud_pak_for_data 2.1 Yes
Application ibm watson_query_with_cloud_pak_for_data 2.2 Yes
Application ibm watson_query_with_cloud_pak_for_data 4.6 Yes
Application ibm watson_query_with_cloud_pak_for_data 4.7 Yes
Application ibm watson_query_with_cloud_pak_for_data 4.8 Yes

References