Description
IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 stores sensitive information in source code could be used by an authenticated user in further attacks against the system.
Published: 2026-09-18
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive information disclosure leading to potential further attacks
Action: Patch Immediately
AI Analysis

Impact

The vulnerability arises because IBM Cognos Analytics stores sensitive data directly in its source code files. An authenticated user can read these files and obtain confidential information, which could then be used to facilitate further attacks such as privilege escalation or data exfiltration. This flaw is a direct information disclosure weakness.

Affected Systems

The affected products are IBM Cognos Analytics. Versions 12.1.0 through 12.1.3, including the first patch release for 12.1.3, as well as 12.0.4 up to its second patch, are impacted. The specific affected releases listed by the vendor include 12.1.0, 12.1.1, 12.1.2, 12.1.3, 12.1.3 FP1, 12.1.3 FP2, 12.0.4, and 12.0.4 FP2.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity. The EPSS score is 0.00295, which is less than 1% and implies a very low but nonzero probability that this vulnerability will be exploited in the wild. No known active exploitation is listed in CISA KEV. The likely attack vector involves an authenticated user accessing the application's source code directory, as inferred from the description. Once the user has access, the exposed data could enable subsequent attacks. Applying the vendor’s patch mitigates the issue.

Generated by OpenCVE AI on September 19, 2026 at 18:24 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. Affected Product(s)Version(s)Fix VersionIBM Cognos Analytics12.1.0, 12.1.1, 12.1.2, 12.1.3, 12.1.3 FP1 12.1.3 FP2 https://www.ibm.com/support/pages/node/7283969 IBM Cognos Analytics12.0.4 - 12.0.4 FP2 12.0.4 FP3 https://www.ibm.com/support/pages/node/7269268


OpenCVE Recommended Actions

  • Apply IBM Cognos Analytics patches 12.1.3 FP2, 12.0.4 FP3, or later releases that address the vulnerability.
  • Review the application source files for any remaining hard‑coded sensitive information and remove it.
  • Restrict authenticated users’ permissions to prevent access to source code directories and enforce the principle of least privilege.

Generated by OpenCVE AI on September 19, 2026 at 18:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 stores sensitive information in source code could be used by an authenticated user in further attacks against the system.
Title IBM Cognos Analytics versions 12.0.4 and 12.1.3 is affected by security vulnerabilities
First Time appeared Ibm
Ibm cognos Analytics
Weaknesses CWE-540
CPEs cpe:2.3:a:ibm:cognos_analytics:12.0.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:12.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:12.1.3:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm cognos Analytics
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Ibm Cognos Analytics
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-18T16:45:07.526Z

Reserved: 2025-04-15T21:16:13.122Z

Link: CVE-2025-36076

cve-icon Vulnrichment

Updated: 2026-09-18T16:45:03.464Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T16:17:02.927

Modified: 2026-09-18T18:17:47.257

Link: CVE-2025-36076

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T18:30:16Z

Weaknesses
  • CWE-540

    Inclusion of Sensitive Information in Source Code