QSearchQSearch

CVE-2025-36221

5.3 MEDIUM

IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System uses default passwords default pa...

Published: 2026-05-26 · Last updated: 2026-06-02

Severity and scoring

CVSS
5.3 MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CWE
CWE-1392

Affected products

VendorProduct
ibmcloud_pak_for_data_system_-_cyclops

Description

IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System uses default passwords default passwords from the manufacturing process for use during the installation process, which could allow an attacker to bypass authentication.

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2026-9330 IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of user-supplied data during deserialization using th... (8.5 HIGH)
  • CVE-2026-9319 IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of untrusted data v... (9.0 CRITICAL)
  • CVE-2026-9311 IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security controls (9.0 CRITICAL)
  • CVE-2026-8644 IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing (9.1 CRITICAL)
  • CVE-2026-1248 IBM Business Automation Workflow containers and traditional may leak information about its database structure in error messages (4.3 MEDIUM)

Same CWE

  • CVE-2026-9844 Use of default credentials vulnerability in Roche Diagnostics navify Digital Pathology (RabbitMQ Management interface modules) allows Def...
  • CVE-2026-42941 The Danelec MacGregor Voyage Data Recorder device includes a default username and password, with no enforced password change (8.3 HIGH)
  • CVE-2026-45039 RustFS is a distributed object storage system built in Rust (9.8 CRITICAL)
  • CVE-2026-7365 IBM Operations Analytics - Log Analysis  and IBM SmartCloud Analytics - Log Analysis uses default passwords default passwords from the ma... (8.4 HIGH)
  • CVE-2026-44159 Tyler Identity Local (TID-L) uses documented, default administrative credentials (9.8 CRITICAL)