Skip to content
IBMCVE-2025-36271

IBM Integrated Analytics System: information disclosure

Medium5.9CVE-2025-36271 · Published Aug 28, 2026 · updated Sep 2, 2026

IBM Integrated Analytics System 1.0.0.0 through 1.0.31.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

IBM advisory

Affected versions

PackageAffectedFixed in
Integrated Analytics System
Product
>= 1.0.0.0, <= 1.0.31.0No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-759

More IBM advisories

All IBM
Advisory
IBM Concert: SQL injection
Critical9.1Aug 28
IBM Cloud Pak for Data System: denial of service
Medium6.2Aug 28
IBM Langflow OSS: path traversal
High7.5Aug 28
IBM Langflow OSS: information disclosure
High8.2Aug 28
IBM Langflow OSS: remote code execution
Critical9.8Aug 28
IBM Langflow OSS: improper authorization
Medium6.4Aug 28

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.