IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 stores unencrypted sensitive information in environmental variables files which can be obtained by an authenticated user.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7253283 |
|
History
Wed, 10 Dec 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:ibm:controller:*:*:*:*:*:*:*:* |
Tue, 09 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 08 Dec 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 stores unencrypted sensitive information in environmental variables files which can be obtained by an authenticated user. | |
| Title | IBM Controller Information Disclosure | |
| First Time appeared |
Ibm
Ibm controller |
|
| Weaknesses | CWE-526 | |
| CPEs | cpe:2.3:a:ibm:controller:11.1.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:controller:11.1.1:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm controller |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published: 2025-12-08T21:37:10.807Z
Updated: 2025-12-09T16:05:34.777Z
Reserved: 2025-04-15T21:16:07.863Z
Link: CVE-2025-36017
Updated: 2025-12-09T15:25:01.450Z
Status : Analyzed
Published: 2025-12-08T22:15:51.513
Modified: 2025-12-10T18:08:41.340
Link: CVE-2025-36017
No data.