Sensitive Information Exposure in IBM Controller and Cognos Controller
CVE-2025-36017
6.5MEDIUM
What is CVE-2025-36017?
The vulnerability in IBM Controller and Cognos Controller allows authenticated users to access sensitive data stored in unencrypted environmental variable files. This exposure can lead to potential data breaches and unauthorized access to confidential information, underscoring the importance of securing environmental variables to prevent information leakage.
Affected Version(s)
Controller 11.1.0 <= 11.1.1
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved