IBM Cognos Controller 11.0.0 through 11.0.1, and IBM Controller 11.1.0 through 11.1.1 could allow an attacker to obtain sensitive information due to the use of hardcoded cryptographic keys for signing session cookies.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.ibm.com/support/pages/node/7246015 |
![]() ![]() |
History
Fri, 03 Oct 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:a:ibm:cognos_controller:*:*:*:*:*:*:*:* cpe:2.3:a:ibm:controller:*:*:*:*:*:*:*:* |
Fri, 26 Sep 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 26 Sep 2025 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | IBM Cognos Controller 11.0.0 through 11.0.1, and IBM Controller 11.1.0 through 11.1.1 could allow an attacker to obtain sensitive information due to the use of hardcoded cryptographic keys for signing session cookies. | |
Title | IBM Controller information disclosure | |
First Time appeared |
Ibm
Ibm cognos Controller Ibm controller |
|
Weaknesses | CWE-321 | |
CPEs | cpe:2.3:a:ibm:cognos_controller:11.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:cognos_controller:11.0.1:*:*:*:*:*:*:* cpe:2.3:a:ibm:controller:11.1.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:controller:11.1.1:*:*:*:*:*:*:* |
|
Vendors & Products |
Ibm
Ibm cognos Controller Ibm controller |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-09-26T14:54:41.385Z
Reserved: 2025-04-15T21:16:51.462Z
Link: CVE-2025-36326

Updated: 2025-09-26T14:54:21.348Z

Status : Analyzed
Published: 2025-09-26T15:16:03.437
Modified: 2025-10-03T19:14:39.327
Link: CVE-2025-36326

No data.

No data.