CVE-2025-36290
IBM Integrated Analytics System 1.0.0.0 through 1.0.31.0 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information using man in the middle techniques.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.9
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS probability
- 0.16%
- CWE
- CWE-295
- Published
- 2026-08-28
- Last modified
- 2026-08-31
Affected products
- IBM Integrated Analytics System
Weakness type
Related vulnerabilities
- CVE-2026-87608 — Improper certificate validation in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging so
- CVE-2026-66795 — Managedcluster-import-controller: csr auto-approver does not validate certificate subject or signername (spoke→hub cluster-admin)
- CVE-2026-78234 — Hawtio-operator: hawtio-operator: service-ca signing oracle allows arbitrary-cn certificate issuance to namespace edit users
- CVE-2026-85102 — Improper Certificate Validation in Quantum Security Gateway
- CVE-2026-32253 — Sunshine: Authentication bypass via improper client certificate validation
- CVE-2026-16835 — Power System Improper Certificate Validation
- CVE-2026-82180 — In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 when the MQTT API is enabled with the certificate authentication polic
- CVE-2026-22093 — Adversary-in-the-Middle (AitM) attack vulnerability in EVbee Service app