Denial of Service Vulnerability in IBM Controller and Cognos Controller
CVE-2025-36015

6.5MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
8 December 2025

What is CVE-2025-36015?

A vulnerability exists in IBM Controller and IBM Cognos Controller that allows an authenticated user to induce a denial of service. This is a result of improper validation of the specified quantity size input, which could potentially disrupt service availability, leaving users unable to access essential functionalities of the affected products.

Affected Version(s)

Cognos Controller 11.0.0 <= 11.0.1 FP6

Controller 11.1.0 <= 11.1.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-36015 : Denial of Service Vulnerability in IBM Controller and Cognos Controller