CVE-2026-17467

8.2

IBM · Cloud Pak for Data System (Yosemite 1.0)

IBM Cloud Pak for Data System (Yosemite 1.0) 3.0.5.2 is vulnerable to information disclosure due to the use of weak or deprecated cryptographic protocols.

Executive summary

A vulnerability in IBM Cloud Pak for Data System allows unauthenticated remote attackers to obtain sensitive information by exploiting weak cryptographic protocols.

Vulnerability

The system improperly utilizes deprecated or weak cryptographic algorithms (CWE-327), which permits an unauthenticated remote attacker to intercept or decrypt sensitive data communications.

Business impact

The use of weak cryptography exposes sensitive organizational data to unauthorized access, potentially leading to a breach of confidentiality and regulatory non-compliance. With a CVSS score of 8.2, this high-severity vulnerability indicates that the attack vector is network-based and does not require user interaction or prior authentication, making it an attractive target for opportunistic attackers.

Remediation

Immediate Action: Upgrade to version 3.0.5.3-WS-ICPDS-NRS-fp346929 as specified in the IBM fix documentation.

Proactive Monitoring: Review network traffic and server access logs for anomalous patterns or connections utilizing legacy protocols such as SSLv3, TLS 1.0, or 1.1.

Compensating Controls: Implement a Web Application Firewall or load balancer to enforce modern, secure TLS configurations and terminate legacy connections before they reach the vulnerable appliance.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS score and the lack of authentication required for exploitation, this vulnerability poses a significant risk to data privacy. Organizations should prioritize the application of the provided vendor patch to ensure that all communications are protected by modern, robust cryptographic standards.

More IBM CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources