CVE-2025-36271
Analyzed Analyzed - Analysis Complete

Weak Cryptographic Algorithms in IBM Integrated Analytics System

Vulnerability report for CVE-2025-36271, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-28

Last updated on: 2026-09-02

Assigner: IBM Corporation

Description

IBM Integrated Analytics System 1.0.0.0 through 1.0.31.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-28
Last Modified
2026-09-02
Generated
2026-09-18
AI Q&A
2026-08-29
EPSS Evaluated
2026-09-15
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ibm integrated_analytics_system From 1.0.0.0 (inc) to 1.0.32.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-759 The product uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the product does not also use a salt as part of the input.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves IBM Integrated Analytics System versions 1.0.0.0 through 1.0.31.0 using weaker than expected cryptographic algorithms. This weakness could allow an attacker to decrypt highly sensitive information that should be protected.

Detection Guidance

This vulnerability involves weak cryptographic algorithms in IBM Integrated Analytics System. Detection requires checking for outdated or insecure cryptographic configurations in the system. Review IBM's documentation for default cryptographic settings and compare against current NIST or industry standards for cryptographic strength.

Impact Analysis

An attacker could exploit this to decrypt sensitive data, potentially exposing confidential information. The impact includes unauthorized access to data that should remain secure, though the CVSS score suggests limited direct impact on system integrity or availability.

Compliance Impact

This vulnerability could lead to non-compliance with data protection regulations like GDPR or HIPAA, as it undermines the confidentiality of sensitive data. Organizations may face legal penalties or reputational damage if such data is exposed due to weak encryption.

Mitigation Strategies

Update IBM Integrated Analytics System to the latest version to ensure stronger cryptographic algorithms are used. Review and replace any instances of weaker encryption methods in use.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-36271. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart