PT-2025-49598 · Ibm · Ibm Controller+1
Published
2025-12-08
·
Updated
2025-12-08
·
CVE-2025-33111
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Controller versions 11.1.0 through 11.1.1
IBM Cognos Controller versions 11.0.0 through 11.0.1 FP6
Description
The software is susceptible to a race condition during the creation of temporary files without utilizing atomic operations. This can potentially expose sensitive information to an authenticated user. The issue involves the insecure handling of temporary file creation, which could allow an attacker to exploit a timing window to access or modify these files.
Recommendations
Update IBM Controller to a version later than 11.1.1.
Update IBM Cognos Controller to a version later than 11.0.1 FP6.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Cognos Controller
Ibm Controller