Ibm Cloud Pak For Data — known CVE vulnerabilities
Every CVE whose affected-product data names Ibm Cloud Pak For Data, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (11)
CVE-2025-14754 — CVSS 8.8 (high): IBM Cloud Pak for Data 5.1.2 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to…
CVE-2025-14753 — CVSS 7.5 (high): IBM Cloud Pak for Data 5.1.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially…
CVE-2022-36769 — CVSS 7.2 (high): IBM Cloud Pak for Data 4.5 and 4.6 could allow a privileged user to upload malicious files of dangerous types that can be automatically…
CVE-2021-20486 — CVSS 6.5 (medium): IBM Cloud Pak for Data 3.0 could allow an authenticated user to obtain sensitive information when installed with additional plugins. IBM…
CVE-2023-26023 — CVSS 6.5 (medium): Planning Analytics Cartridge for Cloud Pak for Data 4.0 exposes sensitive information in logs which could lead an attacker to exploit this…
CVE-2025-0719 — CVSS 6.1 (medium): IBM Cloud Pak for Data 4.0.0 through 4.8.5 and 5.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated…
CVE-2023-27540 — CVSS 5.9 (medium): IBM Watson CP4D Data Stores 4.6.0 does not properly allocate resources without limits or throttling which could allow a remote attacker…
CVE-2023-27877 — CVSS 5.3 (medium): IBM Planning Analytics Cartridge for Cloud Pak for Data 4.0 connects to a CouchDB server. An attacker can exploit an insecure password…
CVE-2023-26026 — CVSS 5.3 (medium): Planning Analytics Cartridge for Cloud Pak for Data 4.0 exposes sensitive information in logs which could lead an attacker to exploit this…
CVE-2021-38899 — CVSS 4.4 (medium): IBM Cloud Pak for Data 2.5 could allow a local user with special privileges to obtain highly sensitive information. IBM X-Force ID: 209575.
CVE-2023-27545 — CVSS 4.0 (medium): IBM Watson CloudPak for Data Data Stores information disclosure 4.6.0 allows web pages to be stored locally which can be read by another…