CVE-2025-33111

IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 is vulnerable to creation of temporary files without atomic operations which may expose sensitive information to an authenticated user due to race condition attacks.
References
Link Resource
https://www.ibm.com/support/pages/node/7253273 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:cognos_controller:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:controller:*:*:*:*:*:*:*:*

History

10 Dec 2025, 18:13

Type Values Removed Values Added
References () https://www.ibm.com/support/pages/node/7253273 - () https://www.ibm.com/support/pages/node/7253273 - Vendor Advisory
First Time Ibm cognos Controller
Ibm controller
Ibm
CPE cpe:2.3:a:ibm:cognos_controller:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:controller:*:*:*:*:*:*:*:*

08 Dec 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-08 22:15

Updated : 2025-12-10 18:13


NVD link : CVE-2025-33111

Mitre link : CVE-2025-33111

CVE.ORG link : CVE-2025-33111


JSON object : View

Products Affected

ibm

  • cognos_controller
  • controller
CWE
CWE-379

Creation of Temporary File in Directory with Insecure Permissions