Sensitive Information Exposure in IBM Knowledge Catalog
CVE-2025-36187

4.4MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
25 March 2026

What is CVE-2025-36187?

The IBM Knowledge Catalog Standard Cartridge contains a vulnerability that allows potentially sensitive information to be stored in log files. This information may be accessed by a local privileged user, posing a significant security risk. Users of versions 5.0.0 through 5.2.1 should take immediate action to secure their systems and limit access to sensitive data. Patching and adhering to security advisories from IBM are crucial for maintaining data integrity and confidentiality.

Affected Version(s)

Knowledge Catalog Standard Cartridge 5.0.0, 5.0.1, 5.0.2, 5.0.3, 5.1, 5.1.1, 5,1.2, 5.1.3, 5.2.0, 5.2.1

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.