CVE-2025-36221
5.3 MEDIUMIBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System uses default passwords default pa...
Published: 2026-05-26 · Last updated: 2026-06-02
Severity and scoring
- CVSS
- 5.3 MEDIUM
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- CWE
- CWE-1392
Affected products
| Vendor | Product |
|---|---|
| ibm | cloud_pak_for_data_system_-_cyclops |
Description
IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System uses default passwords default passwords from the manufacturing process for use during the installation process, which could allow an attacker to bypass authentication.
Source: NVD
References
Related CVEs
Same vendor
- CVE-2026-9330 — IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of user-supplied data during deserialization using th... (8.5 HIGH)
- CVE-2026-9319 — IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of untrusted data v... (9.0 CRITICAL)
- CVE-2026-9311 — IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security controls (9.0 CRITICAL)
- CVE-2026-8644 — IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing (9.1 CRITICAL)
- CVE-2026-1248 — IBM Business Automation Workflow containers and traditional may leak information about its database structure in error messages (4.3 MEDIUM)
Same CWE
- CVE-2026-9844 — Use of default credentials vulnerability in Roche Diagnostics navify Digital Pathology (RabbitMQ Management interface modules) allows Def...
- CVE-2026-42941 — The Danelec MacGregor Voyage Data Recorder device includes a default username and password, with no enforced password change (8.3 HIGH)
- CVE-2026-45039 — RustFS is a distributed object storage system built in Rust (9.8 CRITICAL)
- CVE-2026-7365 — IBM Operations Analytics - Log Analysis and IBM SmartCloud Analytics - Log Analysis uses default passwords default passwords from the ma... (8.4 HIGH)
- CVE-2026-44159 — Tyler Identity Local (TID-L) uses documented, default administrative credentials (9.8 CRITICAL)