Sceawere
Vulnerability Detail
CVE-2026-17467UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
IBM Cloud Pak Weak Cryptography
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.2
- Creation Date
- 3h ago
- Vendor
- IBM
- Product
- Cloud Pak for Data System (Yosemite 1.0)
- Attack Type
- CWE-327 Use of a Broken or Risky Cryptographic Algorithm
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
IBM Cloud Pak for Data System (Yosemite 1.0) 3.0.5.2 could allow a remote attacker to obtain sensitive information due to the use of weak or deprecated cryptographic protocols.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.2",
"pubDate": "2026-09-14T20:16:42.007Z",
"pubdate": "2026-09-14T20:16:42.007Z",
"executiveSummary": "IBM Cloud Pak for Data System (Yosemite 1.0) version 3.0.5.2 is susceptible to an information disclosure vulnerability stemming from the implementation of deprecated or cryptographically weak security protocols.\nThe vulnerability allows a remote, unauthenticated attacker to intercept or decrypt sensitive communications due to the lack of modern, robust encryption standards.\nThis flaw exposes sensitive data to potential man-in-the-middle (MitM) attacks, where traffic may be intercepted and inspected, compromising the confidentiality of internal communication channels.\nThe risk is significant as it undermines the secure transport layer infrastructure of the affected platform. Attackers require network access to the target system to perform interception; no specific user interaction is required for the vulnerability to be exploitable.\nOrganizations relying on this version for data processing or management are at risk of data breaches and exposure of administrative credentials or sensitive telemetry.",
"technicalDetails": "The root cause of this vulnerability lies in the configuration of the Transport Layer Security (TLS) or Secure Sockets Layer (SSL) implementation within IBM Cloud Pak for Data System (Yosemite 1.0) 3.0.5.2. The system supports deprecated or legacy cryptographic protocols that are known to be vulnerable to modern cryptanalysis, such as POODLE, BEAST, or similar protocol-downgrade attacks.\nThe failure to restrict connections to modern, strong protocols (e.g., TLS 1.2 or TLS 1.3) with secure cipher suites facilitates the extraction of plaintext data from supposedly encrypted sessions.\nAttack flow typically begins with an adversary positioned as a man-in-the-middle on the network path between the client and the IBM Cloud Pak for Data System. Through the utilization of a downgrade attack, the attacker forces the communication channel to negotiate the use of the weaker, legacy cryptographic protocol supported by the server.\nOnce the weak protocol is negotiated, the attacker employs standard cryptographic exploitation tools to decrypt the session traffic in real-time or via captured session cookies and payloads.\nThe lack of enforced protocol hardening at the application server or load balancer layer allows these insecure connections to persist. Because the vulnerability exists at the protocol negotiation level, it does not require authentication or elevated privileges to initiate; any remote actor capable of reaching the service interface over the network can attempt to force an insecure handshake.\nPost-exploitation impact includes, but is not limited to, the exposure of sensitive platform metadata, authentication tokens, session identifiers, and potentially proprietary data managed within the Cloud Pak environment. The reliance on weak cipher suites (e.g., those utilizing CBC mode in specific configurations or export-grade ciphers) ensures that once the protocol is downgraded, the encryption is functionally transparent to an adversary.\nThis vulnerability is inherent to the configuration of the service component responsible for managing incoming encrypted connections, which fails to adequately sanitize or reject requests utilizing non-compliant cryptographic standards."
}