Unrated severityNVD Advisory· Published Dec 8, 2025· Updated Dec 9, 2025
IBM Controller Information Disclosure
CVE-2025-36017
Description
IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 stores unencrypted sensitive information in environmental variables files which can be obtained by an authenticated user.
Affected products
3- IBM/Controllerv5cpe:2.3:a:ibm:controller:11.1.0:*:*:*:*:*:*:*Range: 11.1.0
- Range: >=11.1.0 <=11.1.1
- Range: >=11.0.0 <=11.0.1 FP6
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.ibm.com/support/pages/node/7253283mitrevendor-advisorypatch
News mentions
0No linked articles in our index yet.