← Vulnerability feed

Vulnerability record · CVE-2025-36017 · published 8 December 2025

CVE-2025-36017: Ibm controller vulnerability

Ibm · Controller

IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 stores unencrypted sensitive information in environmental variables files which can be obtained by an authenticated user.

6.5 CVSS 3.1 Medium EPSS 0.27% · top 83.4% CWE-526 · CWE-526
6.5CVSS 3.1 base score
0.27%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 stores unencrypted sensitive information in environmental variables files which can be obtained by an authenticated user.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-36017 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2026-5065Ibm controller hard-coded credentials vulnerabilityIBM Controller 11.0.1, 11.1.0, 11.1.1, and 11.1.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own…EPSS 0.33%8.8CVE-2024-28777Ibm cognos controller deserialization of untrusted data vulnerabilityIBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to unrestricted deserialization. This vulnerability allows us…EPSS 0.61%8.8CVE-2024-52902Ibm cognos controller hard-coded credentials vulnerabilityIBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 client application contains hard coded database passwords in source code wh…EPSS 0.36%8.2CVE-2023-47160Ibm cognos controller xml external entity (xxe) vulnerabilityIBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to an XML External Entity Injection (XXE) attack when process…EPSS 0.52%8.2CVE-2024-40702Ibm cognos controller improper certificate validation vulnerabilityIBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow an unauthorized user to obtain valid tokens to gain access to prote…EPSS 0.26%8.0CVE-2024-45084Ibm cognos controller csv injection vulnerabilityIBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 could allow an authenticated attacker to conduct formula injection. An atta…EPSS 0.42%7.5CVE-2025-36326Ibm cognos controller vulnerabilityIBM Cognos Controller 11.0.0 through 11.0.1, and IBM Controller 11.1.0 through 11.1.1 could allow an attacker to obtain sensitive information due to …EPSS 0.23%6.5CVE-2025-36015Ibm cognos controller vulnerabilityIBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 could allow an authenticated user to cause a denial of servi…EPSS 0.29%

Source: NIST National Vulnerability Database (record CVE-2025-36017), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.