CVE-2025-36187 PUBLISHED

Multiple Security vulnerabilities affecting IBM Knowledge Catalog Standard Cartridge

Assigner: ibm
Reserved: 15.04.2025 Published: 25.03.2026 Updated: 25.03.2026

IBM Knowledge Catalog Standard Cartridge 5.0.0, 5.0.1, 5.0.2, 5.0.3, 5.1, 5.1.1, 5,1.2, 5.1.3, 5.2.0, 5.2.1 stores potentially sensitive information in log files that could be read by a local privileged user.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CVSS Score: 4.4

Product Status

Vendor IBM
Product Knowledge Catalog Standard Cartridge
Versions
  • Version 5.0.0, 5.0.1, 5.0.2, 5.0.3, 5.1, 5.1.1, 5,1.2, 5.1.3, 5.2.0, 5.2.1 is affected

Solutions

Affected Product(s)Version(s)IBM Knowledge Catalog Standard Cartridge5.0.0, 5.0.1, 5.0.2, 5.0.3, 5.1, 5.1.1, 5,1.2, 5.1.3, 5.2.0, 5.2.1

References

Problem Types

  • CWE-532 Insertion of Sensitive Information into Log File CWE