CVE-2025-36076 PUBLISHED

IBM Cognos Analytics versions 12.0.4 and 12.1.3 is affected by security vulnerabilities

Assigner: ibm
Reserved: 15.04.2025 Published: 18.09.2026 Updated: 18.09.2026

IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 stores sensitive information in source code could be used by an authenticated user in further attacks against the system.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS Score: 4.3

Product Status

Vendor IBM
Product Cognos Analytics
Versions
  • affected from 12.1.0 to 12.1.3 FP1 (incl.)
  • affected from 12.0.4 to 12.0.4 FP2 (incl.)

Solutions

IBM strongly recommends addressing the vulnerability now.

Affected Product(s)Version(s)Fix VersionIBM Cognos Analytics12.1.0, 12.1.1, 12.1.2, 12.1.3, 12.1.3 FP1 12.1.3 FP2 https://www.ibm.com/support/pages/node/7283969 IBM Cognos Analytics12.0.4 - 12.0.4 FP2 12.0.4 FP3 https://www.ibm.com/support/pages/node/7269268

References

Problem Types

  • CWE-540 Inclusion of Sensitive Information in Source Code CWE