CVE-2025-36271CWE-759

CVE-2025-36271

Medium · published August 29, 2026

CVSS v3.1
5.9
EPSS
0%
Percentile
5.7
In the wild
Unconfirmed
What it is

IBM Integrated Analytics System 1.0.0.0 through 1.0.31.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

The record
Technical detail
CVSS v3.1
5.9 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00162 · 5.7th percentile
Weakness
CWE-759 · Use of a One-Way Hash without a Salt
Published
2026-08-29T02:16Z
Affected products (1)
ProductVersionsFixed in
ibm/integrated_analytics_system≥ 1.0.0.0, < 1.0.32.01.0.32.0
References (1)
EPSS history
Timeline
  • 30 AUG 16:14Z
    EPSS moved — → 0%
    epss
  • 28 AUG 20:41Z
    IBM Integrated Analytics System (IIAS) is affected by a predictable salt vulnerability in Magneto component
    cvelistv5