CVE-2025-36193: IBM Transformation Advisor

Medium severity, CVSS 6.7. EPSS: 0.1% chance of exploitation in the next 30 days.

IBM Transformation Advisor 2.0.1 through 4.3.1 incorrectly assigns privileges to security critical files which could allow a local root escalation inside a container running the IBM Transformation Advisor Operator Catalog image.

Affected products

  • IBM Transformation Advisor: from 2.0.1, before 4.3.2 (fixed in 4.3.2)

Published 2025-09-03. Last modified 2026-06-17.