CVE-2025-13616
HIGHCVSS 7.5/10EPSS 0.23%
Last modified
CVE-2025-13616 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 returns sensitive information in an HTTP response that could be used in further attacks against the system.. EPSS estimates a 0.23% chance of exploitation in the next 30 days.
Description
IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 returns sensitive information in an HTTP response that could be used in further attacks against the system.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Datastage On Cloud Pak For Data | >= 5.1.2, < 5.3.1 |
References
- https://www.ibm.com/support/pages/node/7261771Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-13616?
IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 returns sensitive information in an HTTP response that could be used in further attacks against the system.
How severe is CVE-2025-13616?
CVE-2025-13616 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 0.23% probability of exploitation in the next 30 days.
How do I fix CVE-2025-13616?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-13610The RegistrationMagic – Custom Registration Forms, User Regi…6.4
- CVE-2025-13611GitLab has remediated an issue in GitLab CE/EE affecting all…5.3
- CVE-2025-13612The Album and Image Gallery plus Lightbox plugin for WordPre…6.4
- CVE-2025-13613The Elated Membership plugin for WordPress is vulnerable to …9.8
- CVE-2025-13614The Cool Tag Cloud plugin for WordPress is vulnerable to Sto…8.1
- CVE-2025-13615The StreamTube Core plugin for WordPress is vulnerable to Ar…9.8
- CVE-2025-13617The Apollo13 Framework Extensions plugin for WordPress is vu…6.4
- CVE-2025-13618The Mentoring plugin for WordPress is vulnerable to privileg…9.8
- CVE-2025-13619The Flex Store Users plugin for WordPress is vulnerable to P…9.8
- CVE-2025-1362The URL Shortener | Conversion Tracking | AB Testing | Woo…4.3
- CVE-2025-13620The Wp Social Login and Register Social Counter plugin for W…5.3
- CVE-2025-13621The dream gallery plugin for WordPress is vulnerable to Cros…6.1
Are you affected by CVE-2025-13616?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
