Description
IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
Published: 2026-09-18
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

The vulnerability allows a remote attacker to obtain sensitive information when IBM Controller generates a detailed technical error message in the browser. This information disclosure can provide attackers leverage to launch additional attacks against the system. The weakness is recorded as CWE‑209, which describes improper handling of error messages that expose sensitive data.

Affected Systems

Affected versions include IBM Controller 11.0.0 through 11.0.1 with fix pack 7 and IBM Controller 11.1.0 through 11.1.3 with fix pack 1. Customers running the 11.0 or 11.1 release streams should upgrade to the 11.2 release stream, which incorporates the latest security fixes, at no additional charge.

Risk and Exploitability

The CVSS base score of 5.3 indicates a medium severity of information disclosure. The EPSS score of < 1% provides a very low estimate of exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, implying no known active exploitation. Based on the description, it is inferred that a remote attacker can trigger a detailed error message through the web interface, potentially leaking stack traces or configuration data. While the vulnerability does not directly alter system state, the disclosed information could be used to facilitate further attacks, such as credential theft or privilege escalation, especially if authentication is bypassed or session hijacking occurs.

Generated by OpenCVE AI on September 19, 2026 at 18:09 UTC.

Remediation

Vendor Solution

It is strongly recommended that you apply the most recent security updates: Affected Product(s)Version(s)FixIBM Cognos Controller11.0.0 - 11.0.1 FP7 https://www.ibm.com/mysupport . Customers currently running IBM Controller 11.0 and 11.1 can upgrade to the 11.2 release stream at no additional charge.


OpenCVE Recommended Actions

  • Upgrade IBM Controller to at least version 11.2 or apply the latest available security updates (FP7 for 11.0.0–11.0.1 and FP1 for 11.1.0–11.1.3).
  • If an upgrade cannot be applied immediately, configure IBM Controller to disable verbose technical error messages in the web interface settings to prevent sensitive data leakage.
  • Restrict network access to the controller’s web interface to trusted administrative IP ranges or apply firewall rules to limit exposure to authorized users only.

Generated by OpenCVE AI on September 19, 2026 at 18:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
Title Multiple vulnerabilities in IBM Controller
First Time appeared Ibm
Ibm controller
Weaknesses CWE-209
CPEs cpe:2.3:a:ibm:controller:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:controller:11.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:controller:11.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:controller:11.1.3:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm controller
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-19T14:21:50.638Z

Reserved: 2025-02-15T15:14:07.169Z

Link: CVE-2025-1350

cve-icon Vulnrichment

Updated: 2026-09-19T14:12:15.939Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T15:17:04.343

Modified: 2026-09-19T15:16:56.530

Link: CVE-2025-1350

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T18:15:02Z

Weaknesses
  • CWE-209

    Generation of Error Message Containing Sensitive Information