Impact
IBM Cognos Controller versions 11.0.0 through 11.0.1 FP7 and 11.1.0 through 11.1.3 FP1 transmit sensitive data in clear text, allowing an attacker on the same network to intercept and obtain confidential information via man‑in‑the‑middle techniques. This weakness is identified as improper protection of data in transit (CWE‑319).
Affected Systems
IBM Cognos Controller 11.0.0 and 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 are impacted. Users of these versions are vulnerable until they install the latest security updates or upgrade to the 11.2 release stream, which contains the fix.
Risk and Exploitability
The CVSS score of 5.9 indicates a medium impact level. The EPSS score is 0.00203 (approximately 0.2%), so the likelihood of exploitation remains low, and the vulnerability is not listed in CISA KEV. Based on the description, it is inferred that an attacker would need network access to capture clear‑text traffic, making the attack a passive network interception rather than a traditional exploitation requiring user interaction or elevated privileges.
OpenCVE Enrichment