Metrics
Affected Vendors & Products
No advisories yet.
Solution
Remediation/Fixes It is strongly recommended that you apply the most recent security updates: Affected Product(s) Version(s) Fix IBM Controller 11.1.0 - 11.1.1 Download IBM Controller 11.1.2 from Passport Advantage IBM Cognos Controller 11.0.0 - 11.0.1 FP6 Download IBM Cognos Controller 11.0.1 FP7 from Fix Central IBM Controller 11.1.2 and IBM Cognos Controller 11.0.1 FP7 are available for Cloud deployments.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7253273 |
|
Wed, 10 Dec 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:ibm:cognos_controller:*:*:*:*:*:*:*:* cpe:2.3:a:ibm:controller:*:*:*:*:*:*:*:* |
Tue, 09 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 08 Dec 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 could allow a privileged user to bypass validation, passing user input into the application as trusted data, due to client-side enforcement of server-side security. | |
| Title | IBM Controller Validation Bypass | |
| First Time appeared |
Ibm
Ibm cognos Controller Ibm controller |
|
| Weaknesses | CWE-602 | |
| CPEs | cpe:2.3:a:ibm:cognos_controller:11.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:cognos_controller:11.0.1:FP6:*:*:*:*:*:* cpe:2.3:a:ibm:controller:11.1.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:controller:11.1.1:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm cognos Controller Ibm controller |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-12-09T16:05:50.159Z
Reserved: 2025-04-15T21:16:16.298Z
Link: CVE-2025-36102
Updated: 2025-12-09T15:25:10.429Z
Status : Analyzed
Published: 2025-12-08T22:15:51.687
Modified: 2025-12-10T18:14:44.587
Link: CVE-2025-36102
No data.
OpenCVE Enrichment
No data.