# CVE-2025-36290

## Summary

- **CVE ID:** CVE-2025-36290
- **Severity:** MEDIUM
- **CVSS Score:** 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
- **CWE:** CWE-295
- **Published:** Aug 28, 2026
- **Last Modified:** Aug 31, 2026

## Description

IBM Integrated Analytics System 1.0.0.0 through 1.0.31.0 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information using man in the middle techniques.

## Affected Products

- IBM — Integrated Analytics System (1.0.0.0)

## References

- [CNA](https://www.ibm.com/support/pages/node/7285149)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.16%
- **EPSS Percentile:** 5.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._