Description
IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.
Published: 2026-09-18
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Data Exposure
Action: Immediate Patch
AI Analysis

Impact

IBM Cognos Controller versions 11.0.0 through 11.0.1 FP7 and 11.1.0 through 11.1.3 FP1 transmit sensitive data in clear text, allowing an attacker on the same network to intercept and obtain confidential information via man‑in‑the‑middle techniques. This weakness is identified as improper protection of data in transit (CWE‑319).

Affected Systems

IBM Cognos Controller 11.0.0 and 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 are impacted. Users of these versions are vulnerable until they install the latest security updates or upgrade to the 11.2 release stream, which contains the fix.

Risk and Exploitability

The CVSS score of 5.9 indicates a medium impact level. The EPSS score is 0.00203 (approximately 0.2%), so the likelihood of exploitation remains low, and the vulnerability is not listed in CISA KEV. Based on the description, it is inferred that an attacker would need network access to capture clear‑text traffic, making the attack a passive network interception rather than a traditional exploitation requiring user interaction or elevated privileges.

Generated by OpenCVE AI on September 19, 2026 at 18:03 UTC.

Remediation

Vendor Solution

It is strongly recommended that you apply the most recent security updates: Affected Product(s)Version(s)FixIBM Cognos Controller11.0.0 - 11.0.1 FP7 https://www.ibm.com/mysupport . Customers currently running IBM Controller 11.0 and 11.1 can upgrade to the 11.2 release stream at no additional charge.


OpenCVE Recommended Actions

  • Apply the latest security updates for IBM Cognos Controller 11.0.1 FP7.
  • Apply the latest security updates for IBM Cognos Controller 11.1.3 FP1 or upgrade to the 11.2 release stream.
  • If a patch or upgrade cannot be performed immediately, enforce TLS/SSL or place the controller behind a VPN to prevent clear‑text data transmission.

Generated by OpenCVE AI on September 19, 2026 at 18:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.
Title Multiple vulnerabilities in IBM Controller
First Time appeared Ibm
Ibm controller
Weaknesses CWE-319
CPEs cpe:2.3:a:ibm:controller:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:controller:11.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:controller:11.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:controller:11.1.3:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm controller
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-19T14:21:50.487Z

Reserved: 2025-04-15T21:17:02.754Z

Link: CVE-2025-36421

cve-icon Vulnrichment

Updated: 2026-09-19T14:12:03.744Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T16:17:03.343

Modified: 2026-09-19T15:16:56.660

Link: CVE-2025-36421

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T18:15:02Z

Weaknesses
  • CWE-319

    Cleartext Transmission of Sensitive Information