Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-22137 | IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 could allow malicious actors to view and modify information coming to and from the application which could then be used to access confidential information on the device or network by using a the deprecated or misconfigured AFNetworking library at runtime. |
Solution
IBM encourages customers to update their devices promptly. IBM Cognos Analytics Mobile (iOS) 1.1.0 - 1.1.22 IBM Cognos Analytics Mobile (iOS) 1.1.23
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7239635 |
|
Thu, 07 Aug 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:ibm:cognos_analytics_mobile:*:*:*:*:*:iphone_os:*:* |
Mon, 21 Jul 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 21 Jul 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 could allow malicious actors to view and modify information coming to and from the application which could then be used to access confidential information on the device or network by using a the deprecated or misconfigured AFNetworking library at runtime. | |
| Title | IBM Cognos Analytics Mobile (iOS) information disclosure | |
| First Time appeared |
Ibm
Ibm cognos Analytics Mobile |
|
| Weaknesses | CWE-326 | |
| CPEs | cpe:2.3:a:ibm:cognos_analytics_mobile:1.1.0:*:*:*:*:ios:*:* cpe:2.3:a:ibm:cognos_analytics_mobile:1.1.22:*:*:*:*:ios:*:* |
|
| Vendors & Products |
Ibm
Ibm cognos Analytics Mobile |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-08-18T01:32:49.740Z
Reserved: 2025-04-15T21:16:16.298Z
Link: CVE-2025-36106
Updated: 2025-07-21T18:41:49.667Z
Status : Analyzed
Published: 2025-07-21T19:15:29.157
Modified: 2025-08-07T00:36:14.247
Link: CVE-2025-36106
No data.
OpenCVE Enrichment
No data.
EUVD