IBM Integrated Analytics System 1.0.0.0 through 1.0.31.0 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information using man in the middle techniques.
Advisories
No advisories yet.
Fixes
Solution
Affected Product(s)VRMFRemediation/FixesIBM Integrated Analytics System1.0.32.0 1.0.32.0-IM-IIAS-fp402 https://www.ibm.com/support/fixcentral/swg/selectFixes
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7285149 |
|
History
Fri, 28 Aug 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Integrated Analytics System 1.0.0.0 through 1.0.31.0 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information using man in the middle techniques. | |
| Title | IBM Integrated Analytics System (IIAS) is affected by improper SSL/TLS certificate validation vulnerability in JWT service component | |
| First Time appeared |
Ibm
Ibm integrated Analytics System |
|
| Weaknesses | CWE-295 | |
| CPEs | cpe:2.3:a:ibm:integrated_analytics_system:1.0.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:integrated_analytics_system:1.0.31.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm integrated Analytics System |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-08-28T20:42:23.682Z
Reserved: 2025-04-15T21:16:48.649Z
Link: CVE-2025-36290
No data.
Status : Received
Published: 2026-08-28T22:16:45.757
Modified: 2026-08-28T22:16:45.757
Link: CVE-2025-36290
No data.
OpenCVE Enrichment
No data.
Weaknesses