CVE-2025-36193
BaseFortify
Publication date: 2025-09-03
Last updated on: 2025-09-29
Assigner: IBM Corporation
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ibm | transformation_advisor | From 2.0.1 (inc) to 4.3.2 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-732 | The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in IBM Transformation Advisor versions 2.0.1 through 4.3.1 involves incorrect privilege assignments to security critical files. This flaw could allow a local user to escalate their privileges to root inside a container running the IBM Transformation Advisor Operator Catalog image.
How can this vulnerability impact me? :
The vulnerability can lead to a local root escalation inside the affected container, potentially allowing an attacker with local access to gain full control over the container environment, compromising confidentiality, integrity, and availability of the system.