Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2025-36319

CVE-2025-36319: IBM watsonx.data DoS Vulnerability

CVE-2025-36319 is a denial of service vulnerability in IBM watsonx.data intelligence versions 5.2.0 through 5.3.0. Authenticated users can exploit improper resource throttling to cause temporary service disruption. This article covers technical details, affected versions, impact, and mitigation strategies.

Published:

CVE-2025-36319 Overview

CVE-2025-36319 affects IBM watsonx.data intelligence versions 5.2.0, 5.2.1, 5.2.2, and 5.3.0. The vulnerability allows an authenticated user to trigger a temporary denial of service by sending a specially crafted HTTP request. The root cause is improper allocation of resource throttling [CWE-770], which lets a low-privileged actor consume disproportionate service capacity.

The issue is network-reachable and requires low privileges with no user interaction. Impact is limited to availability, with no confidentiality or integrity consequences.

Critical Impact

An authenticated attacker can cause a temporary denial of service against IBM watsonx.data intelligence by submitting a crafted HTTP request that bypasses resource throttling controls.

Affected Products

  • IBM watsonx.data intelligence 5.2.0
  • IBM watsonx.data intelligence 5.2.1
  • IBM watsonx.data intelligence 5.2.2
  • IBM watsonx.data intelligence 5.3.0

Discovery Timeline

  • 2026-06-30 - CVE-2025-36319 published to NVD
  • 2026-07-01 - Last updated in NVD database

Technical Details for CVE-2025-36319

Vulnerability Analysis

CVE-2025-36319 is a denial of service vulnerability categorized under [CWE-770] Allocation of Resources Without Limits or Throttling. IBM watsonx.data intelligence does not enforce adequate resource controls on certain HTTP request paths. An authenticated user can submit a specially crafted request that consumes server resources beyond expected boundaries.

The result is a temporary loss of availability for the affected service. Because the flaw only affects availability, data confidentiality and integrity remain intact during exploitation. The EPSS probability is 0.422% (percentile 33.965), indicating a low observed likelihood of active exploitation at publication.

Root Cause

The vulnerability stems from improper allocation of resource throttling in the request handling path. The service fails to bound the resources consumed by a single authenticated request or by a request pattern initiated by a single principal. Without correct rate limits, quotas, or backpressure, one caller can degrade service quality for other tenants.

Attack Vector

The attack vector is network-based and requires valid authentication to the watsonx.data intelligence instance. The attacker crafts an HTTP request that triggers the unbounded resource path. No user interaction is required, and no elevated privileges are needed. Refer to the IBM Support Article for vendor-specific technical guidance.

Detection Methods for CVE-2025-36319

Indicators of Compromise

  • Sudden spikes in CPU, memory, or thread utilization on watsonx.data intelligence nodes without corresponding legitimate workload growth.
  • Elevated HTTP request rates or unusually large or complex requests originating from a single authenticated principal.
  • Application timeouts, 503 responses, or degraded API latency observed by downstream consumers.

Detection Strategies

  • Correlate authenticated user identity with per-request resource consumption in application logs to identify outlier callers.
  • Baseline normal request patterns per API endpoint and alert on statistical deviations in payload size, request frequency, or execution time.
  • Monitor watsonx.data intelligence audit logs for repeated requests to endpoints tied to expensive query or ingestion operations.

Monitoring Recommendations

  • Forward application, container, and load balancer logs to a centralized analytics platform for cross-source correlation.
  • Track service-level indicators such as request latency percentiles and error rates and page on sustained degradation.
  • Instrument per-tenant and per-user resource counters so noisy neighbors can be identified quickly.

How to Mitigate CVE-2025-36319

Immediate Actions Required

  • Apply the fixed release documented in the IBM Support Article for CVE-2025-36319.
  • Inventory all IBM watsonx.data intelligence deployments running versions 5.2.0, 5.2.1, 5.2.2, or 5.3.0 and schedule remediation.
  • Restrict access to the watsonx.data intelligence API surface to trusted networks and authenticated principals with least privilege.

Patch Information

IBM has published remediation guidance in the IBM Support Article. Administrators should upgrade to the fixed version identified in that advisory. Validate the upgrade in a staging environment before production rollout to confirm compatibility with existing pipelines.

Workarounds

  • Enforce rate limiting and request size caps at an upstream reverse proxy or API gateway in front of watsonx.data intelligence.
  • Revoke or rotate credentials for accounts that do not require access to the affected APIs to shrink the authenticated attack surface.
  • Configure per-user and per-tenant quotas where supported to bound resource consumption during a denial of service attempt.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.