CVE-2025-12530Disclosure(ibm / software_hub)

LOWCVSS 5.9 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch ibm software_hub systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

IBM watsonx.data intelligence 5.2.2, 5.3.0, 5.3.1, 5.3.1 through Patch 1 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-319

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • software_hub
  • watsonx.data_intelligence

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
software_hubwatsonx.data_intelligence

2 versions affected across 2 products

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-06-30: 2Patch / Workaround · 2026-06-30: 1Technical Details · 2026-06-30: 206-30
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets3 URLs
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2025-12530 IBM http://watsonx.data intelligence 5.2.2, 5.3.0, 5.3.1, 5.3.1 through patch-1 transmits data in clear text that could allow an attacker to obtain sensitive information usi… https://www.cve.org/CVERecord?id=CVE-2025-12530 ----- Traducción: CVE-202… http://infoflow.cloud`

    Post summary

    The post announces CVE-2025-12530, detailing that IBM WatsonX Data Intelligence versions 5.2.2 to 5.3.1 transmit data in clear text, potentially leaking sensitive information. No PoC, exploit, or patch information is provided.

    0000022
    89 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2025-12530 IBM http://watsonx.data intelligence 5.2.2, 5.3.0, 5.3.1, 5.3.1 through patch-1 transmits data in clear text that could allow an attacker to obtain sensitive information usi… https://www.cve.org/CVERecord?id=CVE-2025-12530

    Post summary

    The post details IBM watsonx data intelligence versions that improperly transmit data in clear text, citing CVE‑2025‑12530, and notes a patch‑1 update to mitigate the vulnerability.

    00000562
    57.7K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appibmsoftware_hub---
Appibmsoftware_hub5.3.1--
Appibmsoftware_hub5.3.1--
Appibmwatsonx.data_intelligence---

Explore more