ZeroHour

CVE-2026-17467

niche

Weak Cryptography Exposes Sensitive Data in IBM Cloud Pak for Data System 3.0.5.2

CVSS 3.1
8.2 high
EPSS
Published
()
Modified
AI analysis

IBM Cloud Pak for Data System (Yosemite 1.0) version 3.0.5.2 uses weak or deprecated cryptographic protocols, which could allow a remote attacker with no privileges or user interaction to obtain sensitive information (CWE-327). The flaw is triggered by an attacker connecting to, or interposing themselves against, appliance services that still negotiate outdated protocols or cipher suites — for example by downgrading a session or passively capturing traffic that weak algorithms fail to protect. Successful exploitation yields high confidentiality impact (decrypted or intercepted sensitive data such as credentials and customer information) and low integrity impact, with no availability impact, reflected in a CVSS 3.1 base score of 8.2 (high). Organizations running the affected on-premises appliance release are exposed wherever its interfaces accept weak protocols. The issue is not listed in CISA's KEV catalog and no public proof-of-concept or observed in-the-wild exploitation is known.

What to do: Apply IBM's fix for this advisory and move off Cloud Pak for Data System 3.0.5.2 (Yosemite 1.0) as soon as a patched release is available. Until then, disable deprecated protocols and weak cipher suites (e.g., SSLv3, TLS 1.0/1.1, export/null ciphers) on all appliance interfaces and restrict management and data-service ports to trusted networks or VPN. Verify remediation with a TLS configuration scan against every exposed endpoint on the appliance to confirm only modern protocols and strong ciphers are negotiated.

Affected
IBM Cloud Pak for Data System (Yosemite 1.0)3.0.5.2
Estimated exposure
nichelikely hundreds to low thousands of enterprise appliance deployments worldwide (exact count unknown) — Cloud Pak for Data System is an on-premises enterprise integrated appliance with no public install counts or internet-wide scan data available, so exposure is limited to the comparatively small population of organizations that own these…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM Cloud Pak for Data System (Yosemite 1.0) 3.0.5.2 could allow a remote attacker to obtain sensitive information due to the use of weak or deprecated cryptographic protocols.

Weakness
CWE-327
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.