IBM watsonx.data 2.2 through 2.2.1 IBM Lakehouse could allow a privileged user to upload malicious files that could be executed server to modify limited files or data.

Project Subscriptions

Vendors Products
Watsonx.data Subscribe
Watsonxdata Subscribe
Advisories

No advisories yet.

Fixes

Solution

The product needs to be installed or upgraded to the latest available level watsonx.data 2.2.2 or watsonx.data on CPD 5.2.2.  Installation/upgrade instructions can be found here: https://www.ibm.com/docs/en/watsonx/watsonxdata/5.2.x?topic=deployment-installing .


Workaround

No workaround given by the vendor.

History

Fri, 20 Feb 2026 18:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:watsonx.data:*:*:*:*:*:*:*:*

Wed, 18 Feb 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 18 Feb 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Ibm watsonx.data
Vendors & Products Ibm watsonx.data

Tue, 17 Feb 2026 22:00:00 +0000

Type Values Removed Values Added
Description IBM watsonx.data 2.2 through 2.2.1 IBM Lakehouse could allow a privileged user to upload malicious files that could be executed server to modify limited files or data.
Title Privileged User File Upload Vulnerability Leading to Limited Server-Side Execution affects watsonx.data
First Time appeared Ibm
Ibm watsonxdata
Weaknesses CWE-434
CPEs cpe:2.3:a:ibm:watsonxdata:2.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:watsonxdata:2.2.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:watsonxdata:2.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm watsonxdata
References
Metrics cvssV3_1

{'score': 3.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-02-18T20:36:53.178Z

Reserved: 2025-04-15T21:16:23.419Z

Link: CVE-2025-36183

cve-icon Vulnrichment

Updated: 2026-02-18T20:36:48.536Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-17T22:18:43.620

Modified: 2026-02-20T17:57:13.307

Link: CVE-2025-36183

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-02-18T10:33:11Z

Weaknesses