Sensitive Information Exposure in IBM Cognos Analytics
CVE-2025-36076
4.3MEDIUM
What is CVE-2025-36076?
IBM Cognos Analytics versions 12.1.0 through 12.1.3 FP1 and 12.0.4 through 12.0.4 FP2 are susceptible to a vulnerability where sensitive information is stored in the source code. This flaw can be exploited by authenticated users to conduct further attacks, potentially leading to unauthorized access to confidential data or manipulation of the system.
Affected Version(s)
Cognos Analytics 12.1.0 <= 12.1.3 FP1
Cognos Analytics 12.0.4 <= 12.0.4 FP2