IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 stores unencrypted sensitive information in environmental variables files which can be obtained by an authenticated user.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7253283 |
|
History
Tue, 09 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 08 Dec 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 stores unencrypted sensitive information in environmental variables files which can be obtained by an authenticated user. | |
| Title | IBM Controller Information Disclosure | |
| First Time appeared |
Ibm
Ibm controller |
|
| Weaknesses | CWE-526 | |
| CPEs | cpe:2.3:a:ibm:controller:11.1.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:controller:11.1.1:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm controller |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published: 2025-12-08T21:37:10.807Z
Updated: 2025-12-09T16:05:34.777Z
Reserved: 2025-04-15T21:16:07.863Z
Link: CVE-2025-36017
Updated: 2025-12-09T15:25:01.450Z
Status : Awaiting Analysis
Published: 2025-12-08T22:15:51.513
Modified: 2025-12-09T18:37:33.427
Link: CVE-2025-36017
No data.