cloud_pak_for_data vulnerabilities
CVEs whose affected-version data names the cloud_pak_for_data package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2025-14753High· 7.5IBM Cloud Pak for Data 5.1.2 could allow a remote attacker to traverse directories on the system
IBM Cloud Pak for Data 5.1.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
▾ TwilightIBM · Cloud Pak for DataEPSS 0.62%via NVD
CVE-2025-14754High· 8.8IBM Cloud Pak for Data 5.1.2 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.
IBM Cloud Pak for Data 5.1.2 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.
▾ TwilightIBM · Cloud Pak for DataEPSS 0.65%via NVD