CVE-2024-37526 Details
Description
IBM Watson Query on Cloud Pak for Data (IBM Data Virtualization 1.8, 2.0, 2.1, 2.2, and 3.0.0) could allow an authenticated user to obtain sensitive information from objects published using Watson Query due to an improper data protection mechanism.
A vulnerability exists in IBM Watson Query on Cloud Pak for Data, specifically in the Data Virtualization components of versions 1.8, 2.0, 2.1, 2.2, and 3.0.0. This vulnerability could enable an authenticated user to access sensitive information from objects published through Watson Query. The issue arises from an inadequate data protection mechanism, which fails to govern all columns of published objects, leaving certain sensitive data unprotected.
Users are advised to upgrade to IBM Data Virtualization on Cloud Pak for Data version 5.0.1 or later, or IBM Watson Query on Cloud Pak for Data version 4.8.6 or later. After upgrading, identify all Data Virtualization objects with more than 100 columns, re-publish them to governed catalogs, and delete the original catalog asset according to the configured catalog de-duplication logic.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 28, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.ibm.com/support/pages/node/7173774 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-497 | Exposure of Sensitive System Information to an Unauthorized Control Sphere | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ibm data virtualization on cloud pak for data | 1.8.0 3.0.0 4.5.0 5.0.0 |
CPE
Remediation
| |
| ibm watson query with cloud pak for data | 2.0 2.1 2.2 4.6 4.7 4.8 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 18, 2025 | Initial Analysis | [email protected] |
| Jan 27, 2025 | New CVE Received | [email protected] |