CVE-2025-33111: IBM Controller Information Disclosure
IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 is vulnerable to creation of temporary files without atomic operations which may expose sensitive information to an authenticated user due to race condition attacks.
Other sources
IBM Controller is vulnerable to creation of temporary files without atomic operations which may expose sensitive information to an authenticated user due to race condition attacks.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-33111?
CVE-2025-33111 has been assessed as a high severity vulnerability due to the potential exposure of sensitive information.
How do I fix CVE-2025-33111?
To fix CVE-2025-33111, update IBM Controller to version 11.1.2 or later and IBM Cognos Controller to version 11.0.2 or later.
Who is affected by CVE-2025-33111?
CVE-2025-33111 affects users of IBM Controller versions 11.1.0 to 11.1.1 and IBM Cognos Controller versions 11.0.0 to 11.0.1 FP6.
What type of attack does CVE-2025-33111 enable?
CVE-2025-33111 enables race condition attacks which can lead to the creation of temporary files that expose sensitive information.
Is CVE-2025-33111 exploitable by unauthenticated users?
No, CVE-2025-33111 can only be exploited by authenticated users.