CVE-2025-36017

IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 stores unencrypted sensitive information in environmental variables files which can be obtained by an authenticated user.
References
Link Resource
https://www.ibm.com/support/pages/node/7253283 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:ibm:controller:*:*:*:*:*:*:*:*

History

10 Dec 2025, 18:08

Type Values Removed Values Added
CPE cpe:2.3:a:ibm:controller:*:*:*:*:*:*:*:*
References () https://www.ibm.com/support/pages/node/7253283 - () https://www.ibm.com/support/pages/node/7253283 - Vendor Advisory
First Time Ibm controller
Ibm

08 Dec 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-08 22:15

Updated : 2025-12-10 18:08


NVD link : CVE-2025-36017

Mitre link : CVE-2025-36017

CVE.ORG link : CVE-2025-36017


JSON object : View

Products Affected

ibm

  • controller
CWE
CWE-526

Cleartext Storage of Sensitive Information in an Environment Variable