ZeroHour

CVE-2025-36326

CVSS 3.1
7.5 high
EPSS
<1%p14
Published
()
Modified
Description

IBM Cognos Controller 11.0.0 through 11.0.1, and IBM Controller 11.1.0 through 11.1.1 could allow an attacker to obtain sensitive information due to the use of hardcoded cryptographic keys for signing session cookies.

Vendors
ibm
Products
cognos controller, controller
Weakness
CWE-321
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.