PT-2025-39647 · Ibm · Ibm Controller+1

Published

2025-09-25

·

Updated

2025-09-29

·

CVE-2025-36326

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Cognos Controller versions 11.0.0 through 11.0.1 IBM Controller versions 11.1.0 through 11.1.1
Description The software uses hardcoded cryptographic keys for signing session cookies, potentially allowing an attacker to obtain sensitive information.
Recommendations Update IBM Cognos Controller to a version later than 11.0.1. Update IBM Controller to a version later than 11.1.1.

Fix

Weakness Enumeration

Related Identifiers

BDU:2025-16002
CVE-2025-36326

Affected Products

Ibm Cognos Controller
Ibm Controller