Input Validation Vulnerability in IBM Controller Product Line
CVE-2025-36178

5.4MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
18 September 2026

What is CVE-2025-36178?

IBM Controller versions 11.0.0 FP7, 11.0.1 FP7, 11.1.0 FP1, and 11.1.3 FP1 are vulnerable to a bypass of input validation measures, enabling an authenticated user to manipulate the client-side input related to file size. This vulnerability stems from improper validation processes, which can compromise the integrity of data handling in affected products, potentially leading to unauthorized access or manipulation of system resources.

Affected Version(s)

Controller 11.0.0 <= 11.0.1 FP7

Controller 11.1.0 <= 11.1.3 FP1

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.