CVE-2026-17467
nicheWeak Cryptography Exposes Sensitive Data in IBM Cloud Pak for Data System 3.0.5.2
IBM Cloud Pak for Data System (Yosemite 1.0) version 3.0.5.2 uses weak or deprecated cryptographic protocols, which could allow a remote attacker with no privileges or user interaction to obtain sensitive information (CWE-327). The flaw is triggered by an attacker connecting to, or interposing themselves against, appliance services that still negotiate outdated protocols or cipher suites — for example by downgrading a session or passively capturing traffic that weak algorithms fail to protect. Successful exploitation yields high confidentiality impact (decrypted or intercepted sensitive data such as credentials and customer information) and low integrity impact, with no availability impact, reflected in a CVSS 3.1 base score of 8.2 (high). Organizations running the affected on-premises appliance release are exposed wherever its interfaces accept weak protocols. The issue is not listed in CISA's KEV catalog and no public proof-of-concept or observed in-the-wild exploitation is known.
What to do: Apply IBM's fix for this advisory and move off Cloud Pak for Data System 3.0.5.2 (Yosemite 1.0) as soon as a patched release is available. Until then, disable deprecated protocols and weak cipher suites (e.g., SSLv3, TLS 1.0/1.1, export/null ciphers) on all appliance interfaces and restrict management and data-service ports to trusted networks or VPN. Verify remediation with a TLS configuration scan against every exposed endpoint on the appliance to confirm only modern protocols and strong ciphers are negotiated.
| IBM Cloud Pak for Data System (Yosemite 1.0) | 3.0.5.2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM Cloud Pak for Data System (Yosemite 1.0) 3.0.5.2 could allow a remote attacker to obtain sensitive information due to the use of weak or deprecated cryptographic protocols.
- Weakness
- CWE-327
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.