CVE-2025-36220
Analyzed Analyzed - Analysis Complete
SQL Injection in IBM Cloud Pak for Data System

Publication date: 2026-05-26

Last updated on: 2026-06-02

Assigner: IBM Corporation

Description
IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-05-26
Last Modified
2026-06-02
Generated
2026-06-16
AI Q&A
2026-05-27
EPSS Evaluated
2026-06-14
NVD
EUVD
Affected Vendors & Products
Showing 3 associated CPEs
Vendor Product Version / Range
ibm cloud_pak_for_data_system_-_cyclops to 11.3.0.2 (exc)
ibm cloud_pak_for_data_system_-_cyclops 11.3.0.2
ibm cloud_pak_for_data_system_-_cyclops 11.3.0.2
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-89 The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Detection Guidance

There are no specific detection commands or methods provided in the available information for identifying this SQL injection vulnerability on your network or system.

The recommended action is to update IBM Cloud Pak for Data System to the fixed version 11.3.1.1-WS-ICPDS-CYCLOPS-fp278500, as no workarounds or detection commands are currently available.

Executive Summary

CVE-2025-36220 is an SQL injection vulnerability in IBM Cloud Pak for Data System - Cyclops versions 11.3.0.2 through Interim Fix 002. This flaw allows a remote attacker to send specially crafted SQL statements that exploit improper neutralization of special elements in SQL commands.

By exploiting this vulnerability, the attacker could view, add, modify, or delete information stored in the back-end database.

Impact Analysis

This vulnerability can impact you by allowing a remote attacker to manipulate your database through SQL injection. Specifically, the attacker could view sensitive data, add unauthorized data, modify existing data, or delete important information in the back-end database.

The attack requires only network access and low privileges, and no user interaction is needed, making it easier for attackers to exploit.

The severity is rated as medium with a CVSS base score of 4.3.

Mitigation Strategies

The vulnerability in IBM Cloud Pak for Data System Cyclops (version 11.3.0.2-IF2) is an SQL injection flaw that can be exploited remotely.

There are no workarounds currently available to mitigate this issue.

The immediate step to mitigate this vulnerability is to update the IBM Cloud Pak for Data System to the fixed version 11.3.1.1-WS-ICPDS-CYCLOPS-fp278500 provided by IBM.

Compliance Impact

The vulnerability allows a remote attacker to view, add, modify, or delete information in the back-end database via SQL injection.

Such unauthorized access and manipulation of data could potentially lead to non-compliance with data protection regulations like GDPR and HIPAA, which require the protection of sensitive data from unauthorized access and alteration.

However, the provided information does not explicitly state the impact on compliance with these standards.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-36220. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart