Published On: Sep 29, 2025 15:03
Advisory No: TZCERT-SA-25-0115
Source: IBM
Software Affected: IBM watsonx, IBM Master Data Management
IBM products are vulnerable to critical vulnerabilities. Exploitation of these vulnerabilities may allow an unauthenticated attacker to execute arbitrary code.
IBM watsonx and IBM Master Data Management, maintaining Apache Tomcat and IBM WebSphere Application Server, are affected by the vulnerabilities tracked as CVE-2025-24813 and CVE-2025-36038 with CVSS scores of 9.8 and 9.0, respectively. The plugins are vulnerable due to a deserialization attack. The vulnerabilities allow attackers to send a specially crafted request to execute arbitrary code on the affected system.
Successful exploitation of these vulnerabilities may allow the attackers to take control of the affected system.
IBM has released security patches for these vulnerabilities. Users and administrators are encouraged to apply necessary updates.
A digest of Tanzania Computer Emergency Response Team coverage of cyber-security news across the globe.