Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2025-36333

CVE-2025-36333: IBM watsonx.data Auth Bypass Vulnerability

CVE-2025-36333 is an authentication bypass vulnerability in IBM watsonx.data intelligence that allows authenticated users to perform unauthorized actions. This post covers technical details, affected versions, impact, and mitigation.

Published:

CVE-2025-36333 Overview

CVE-2025-36333 affects IBM watsonx.data intelligence versions 5.2.0, 5.2.1, 5.2.2, and 5.3.0. The vulnerability allows an authenticated user to perform unauthorized actions due to improper enforcement of behavioral workflow [CWE-841]. Attackers with valid low-privilege credentials can bypass expected workflow states and invoke actions outside their authorized sequence. The flaw affects the integrity of workflow-controlled operations within the platform but does not expose confidentiality or availability.

Critical Impact

Authenticated users can bypass workflow controls in IBM watsonx.data intelligence to perform unauthorized actions, undermining data governance and pipeline integrity.

Affected Products

  • IBM watsonx.data intelligence 5.2.0
  • IBM watsonx.data intelligence 5.2.1
  • IBM watsonx.data intelligence 5.2.2
  • IBM watsonx.data intelligence 5.3.0

Discovery Timeline

  • 2026-06-30 - CVE-2025-36333 published to NVD
  • 2026-07-01 - Last updated in NVD database

Technical Details for CVE-2025-36333

Vulnerability Analysis

The vulnerability is classified under [CWE-841] Improper Enforcement of Behavioral Workflow. IBM watsonx.data intelligence enforces sequences of operations that must occur in a specific order or state. The affected versions fail to validate that required preceding states have been reached before permitting subsequent actions.

An authenticated user with low privileges can invoke workflow operations out of order. This allows the attacker to influence workflow-driven decisions, skip approval or validation stages, or alter records that should be protected by state transitions. The impact centers on integrity rather than data exposure or service disruption.

The attack is executed over the network against exposed watsonx.data intelligence endpoints. Exploitation requires valid credentials but no user interaction. Complexity is low because the flaw resides in server-side state validation rather than in a race or timing condition.

Root Cause

The root cause is missing or insufficient server-side checks that verify a workflow object is in the correct prerequisite state before executing an action. When the application relies on client-driven workflow steps without re-validating state transitions on the backend, an authenticated caller can submit requests that skip mandatory stages.

Attack Vector

Exploitation requires network access to the watsonx.data intelligence API and valid authenticated user credentials. The attacker crafts API requests targeting workflow-governed operations and submits them in an unexpected order. Because behavioral workflow enforcement is incomplete, the server processes requests that should have been rejected. Refer to the IBM Support Page for vendor technical details.

No public proof-of-concept is available. The EPSS probability is 0.277%, indicating low near-term exploitation likelihood.

Detection Methods for CVE-2025-36333

Indicators of Compromise

  • Workflow objects transitioning to states without corresponding preceding actions in audit logs.
  • API requests from authenticated users targeting workflow endpoints in unusual sequences.
  • Modifications to governed data assets by accounts that did not complete required approval steps.

Detection Strategies

  • Enable and review watsonx.data intelligence audit logging for all workflow state transitions and correlate with the user identity performing each action.
  • Baseline expected workflow sequences per role and alert on requests that skip mandatory steps.
  • Monitor for repeated API calls to workflow-governed endpoints from a single authenticated principal within short time windows.

Monitoring Recommendations

  • Forward watsonx.data intelligence application and API logs to a centralized SIEM for continuous review.
  • Track privileged and low-privileged account activity against workflow endpoints and alert on anomalies.
  • Review governance and data catalog change history for unexpected modifications following the CVE publication date.

How to Mitigate CVE-2025-36333

Immediate Actions Required

  • Upgrade IBM watsonx.data intelligence to the fixed version referenced in the IBM Support Page.
  • Audit user accounts and reduce privileges for accounts that do not require workflow authoring or approval roles.
  • Review workflow audit logs for out-of-sequence actions dating back to deployment of affected versions.

Patch Information

IBM has published guidance and remediation details for CVE-2025-36333 on the IBM Support Page. Administrators running versions 5.2.0, 5.2.1, 5.2.2, or 5.3.0 should apply the vendor-supplied fix following IBM's upgrade procedure for watsonx.data intelligence.

Workarounds

  • Restrict network access to watsonx.data intelligence APIs to trusted management networks until patching is complete.
  • Enforce least privilege by removing workflow-related permissions from accounts that do not require them.
  • Enable enhanced audit logging and manually review workflow transitions until the patched version is deployed.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.