Two Critical Vulnerabilities in Multiple IBM Products (CVE-2025-24813, CVE-2025-36038)

Published On: Sep 29, 2025 15:03

Advisory No: TZCERT-SA-25-0115

Source: IBM

Software Affected: IBM watsonx, IBM Master Data Management

Overview

IBM products are vulnerable to critical vulnerabilities. Exploitation of these vulnerabilities may allow an unauthenticated attacker to execute arbitrary code.

Description

IBM watsonx and IBM Master Data Management, maintaining Apache Tomcat and IBM WebSphere Application Server, are affected by the vulnerabilities tracked as CVE-2025-24813 and CVE-2025-36038 with CVSS scores of 9.8 and 9.0, respectively. The plugins are vulnerable due to a deserialization attack. The vulnerabilities allow attackers to send a specially crafted request to execute arbitrary code on the affected system.

Impact

Successful exploitation of these vulnerabilities may allow the attackers to take control of the affected system.

Solution

IBM has released security patches for these vulnerabilities. Users and administrators are encouraged to apply necessary updates.

Subscribe To TZ - CERT Newsletter

A digest of Tanzania Computer Emergency Response Team coverage of cyber-security news across the globe.

Subscribe
Report Incident