Remote Information Disclosure in IBM Analytics Content Hub
CVE-2025-36090

4.3MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
10 July 2025

What is CVE-2025-36090?

IBM Analytics Content Hub versions 2.0 through 2.3 have a vulnerability that may allow remote attackers to gain unauthorized access to information pertaining to the application framework. This could occur as a result of detailed error messages being exposed, which could assist attackers in performing reconnaissance to facilitate future attacks. Mitigation strategies should be implemented to protect sensitive information from being disclosed.

Affected Version(s)

Analytics Content Hub 2.0, 2.1, 2.2, 2.3

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-36090 : Remote Information Disclosure in IBM Analytics Content Hub