Skip to main content

CVE-2025-36174: CWE-434 Unrestricted Upload of File with Dangerous Type in IBM Integrated Analytics System

High
VulnerabilityCVE-2025-36174cvecve-2025-36174cwe-434
Published: Sun Aug 24 2025 (08/24/2025, 01:21:41 UTC)
Source: CVE Database V5
Vendor/Project: IBM
Product: Integrated Analytics System

Description

IBM Integrated Analytics System 1.0.0.0 through 1.0.30.0 could allow an authenticated user to upload a file with dangerous types that could be executed by another user if opened.

AI-Powered Analysis

AILast updated: 08/24/2025, 01:47:42 UTC

Technical Analysis

CVE-2025-36174 is a high-severity vulnerability identified in IBM Integrated Analytics System versions 1.0.0.0 through 1.0.30.0. The vulnerability is classified under CWE-434, which pertains to the unrestricted upload of files with dangerous types. Specifically, this flaw allows an authenticated user to upload files that may contain executable code or scripts. If another user subsequently opens or interacts with these files, the malicious content could be executed, potentially leading to unauthorized code execution, data compromise, or system manipulation. The vulnerability requires the attacker to have valid credentials (authenticated access) and involves some degree of user interaction (the victim opening the malicious file). The CVSS 3.1 base score is 8.0, reflecting high impact on confidentiality, integrity, and availability, with network attack vector, low attack complexity, and privileges required. The vulnerability affects the IBM Integrated Analytics System, a platform used for data analytics and business intelligence, which often handles sensitive organizational data. No known exploits are currently reported in the wild, and no patches have been published as of the vulnerability disclosure date (August 24, 2025). The lack of file type restrictions in the upload functionality is the root cause, enabling potentially dangerous file types to be stored and later executed, which can lead to remote code execution or privilege escalation if exploited successfully.

Potential Impact

For European organizations using IBM Integrated Analytics System, this vulnerability poses significant risks. Given the platform's role in processing and analyzing critical business data, exploitation could lead to unauthorized access to sensitive analytics results, intellectual property theft, or manipulation of data integrity. The ability to execute malicious code via uploaded files could allow attackers to move laterally within the network, escalate privileges, or disrupt analytics services, impacting business continuity. Furthermore, the breach of confidentiality and integrity could have regulatory implications under GDPR, potentially resulting in fines and reputational damage. The requirement for authentication somewhat limits the attack surface to insiders or compromised accounts, but the risk remains substantial in environments with multiple users or insufficient access controls. The absence of known exploits suggests a window of opportunity for proactive mitigation before widespread attacks occur.

Mitigation Recommendations

Organizations should implement strict access controls and monitor user activities within the IBM Integrated Analytics System to detect anomalous file uploads. Until IBM releases an official patch, administrators should consider disabling or restricting file upload functionalities where possible, or enforce manual review and validation of uploaded files. Employing network segmentation to isolate the analytics system can limit lateral movement if exploitation occurs. Additionally, deploying endpoint protection and application whitelisting on client machines can prevent execution of unauthorized files. User education to avoid opening suspicious files within the system is critical. Regularly auditing user privileges to minimize the number of users with upload permissions reduces risk. Finally, organizations should maintain up-to-date backups of analytics data to enable recovery in case of compromise.

Need more detailed analysis?Get Pro

Technical Details

Data Version
5.1
Assigner Short Name
ibm
Date Reserved
2025-04-15T21:16:22.577Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 68aa6bbbad5a09ad002d0c36

Added to database: 8/24/2025, 1:32:43 AM

Last enriched: 8/24/2025, 1:47:42 AM

Last updated: 8/24/2025, 8:00:25 AM

Views: 7

Actions

PRO

Updates to AI analysis are available only with a Pro account. Contact root@offseq.com for access.

Please log in to the Console to use AI analysis features.

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats