CVE-2025-36421 PUBLISHED

Multiple vulnerabilities in IBM Controller

Assigner: ibm
Reserved: 15.04.2025 Published: 18.09.2026 Updated: 18.09.2026

IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS Score: 5.9

Product Status

Vendor IBM
Product Controller
Versions
  • affected from 11.0.0 to 11.0.1 FP7 (incl.)
  • affected from 11.1.0 to 11.1.3 FP1 (incl.)

Solutions

It is strongly recommended that you apply the most recent security updates:

Affected Product(s)Version(s)FixIBM Cognos Controller11.0.0 - 11.0.1 FP7 https://www.ibm.com/mysupport . Customers currently running IBM Controller 11.0 and 11.1 can upgrade to the 11.2 release stream at no additional charge.

References

Problem Types

  • CWE-319 Cleartext Transmission of Sensitive Information CWE