Authentication Bypass Vulnerability in IBM Cognos Analytics Mobile App
CVE-2025-36057

5.2MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
21 July 2025

What is CVE-2025-36057?

IBM Cognos Analytics Mobile for iOS versions 1.1.0 to 1.1.22 is susceptible to an authentication bypass due to reliance on the Local Authentication Framework library, which is unnecessary since biometric authentication is not utilized within the application. This flaw potentially allows unauthorized access to sensitive features of the app, exposing user data and application integrity.

Affected Version(s)

Cognos Analytics Mobile iOS 1.1.0 <= 1.1.22

References

CVSS V3.1

Score:
5.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.