Description
IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 could allow an authenticated user to bypass input validation due to improper validation of client-side input of file size.
Published: 2026-09-18
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authentication-based Input Validation Bypass
Action: Apply patch
AI Analysis

Impact

IBM Controller versions 11.0.0 through 11.0.1 FP7 and 11.1.0 through 11.1.3 FP1 contain a flaw that allows an authenticated user to bypass client‑side input validation of the file size field, enabling the upload of files larger than intended limits. Such oversized uploads can lead to resource exhaustion or allow the delivery of payloads that would normally be rejected, potentially compromising application functionality or exposing sensitive data.

Affected Systems

The affected systems are IBM Controller installations running any of the following releases: 11.0.0, 11.0.1 (fixed in FP7), 11.1.0, 11.1.3 (fixed in FP1). Users on the 11.0 or 11.1 release streams are advised to upgrade to the 11.2 stream, which includes the necessary fixes and is available at no additional charge.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate severity, and the EPSS score is < 1%. This vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an authenticated user exploiting the client‑side interface; no elevated privileges are required beyond valid user credentials. The overall risk is therefore moderate and should be mitigated promptly by applying the available updates.

Generated by OpenCVE AI on September 19, 2026 at 17:22 UTC.

Remediation

Vendor Solution

It is strongly recommended that you apply the most recent security updates: Affected Product(s)Version(s)FixIBM Cognos Controller11.0.0 - 11.0.1 FP7 https://www.ibm.com/mysupport . Customers currently running IBM Controller 11.0 and 11.1 can upgrade to the 11.2 release stream at no additional charge.


OpenCVE Recommended Actions

  • Apply the most recent security updates for IBM Controller; if on the 11.0 or 11.1 release streams, upgrade to the 11.2 release stream to obtain the fix.
  • For installations remaining on 11.0.x or 11.1.x, ensure that the FP7 or FP1 patches, respectively, are applied.
  • As an interim measure, enforce server‑side file size validation to prevent oversized uploads until the official update is in place.

Generated by OpenCVE AI on September 19, 2026 at 17:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 could allow an authenticated user to bypass input validation due to improper validation of client-side input of file size.
Title Multiple vulnerabilities in IBM Controller
First Time appeared Ibm
Ibm controller
Weaknesses CWE-1284
CPEs cpe:2.3:a:ibm:controller:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:controller:11.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:controller:11.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:controller:11.1.3:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm controller
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-18T17:39:45.236Z

Reserved: 2025-04-15T21:16:22.578Z

Link: CVE-2025-36178

cve-icon Vulnrichment

Updated: 2026-09-18T17:39:38.203Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T16:17:03.200

Modified: 2026-09-18T18:17:47.257

Link: CVE-2025-36178

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T17:30:07Z

Weaknesses
  • CWE-1284

    Improper Validation of Specified Quantity in Input