3.7
/ 10
LOW
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Description
IBM Cognos Controller 11.0.0 through 11.0.1, and IBM Controller 11.1.0 through 11.1.1 could allow an attacker to obtain sensitive information due to the use of hardcoded cryptographic keys for signing session cookies.
Basic Information
ID
CVE-2025-36326
Source
ibm
Published
Sep 26, 2025 at 14:20
Modified
Sep 26, 2025 at 14:54
Affected Product
Vendor
IBM
Product
Cognos Controller
Version
11.0.0
Affected Versions
IBM Cognos Controller 11.0.0
IBM Controller 11.1.0
IBM Controller 11.1.0