CVE-2025-36017: IBM Controller Information Disclosure
IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 stores unencrypted sensitive information in environmental variables files which can be obtained by an authenticated user.
Other sources
IBM Controller stores unencrypted sensitive information in environmental variables files which can be obtained by an authenticated user.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36017?
CVE-2025-36017 is classified as a high severity vulnerability due to the exposure of unencrypted sensitive information.
How can I mitigate CVE-2025-36017?
To mitigate CVE-2025-36017, ensure that sensitive information is encrypted before being stored in environmental variable files.
Who is affected by CVE-2025-36017?
CVE-2025-36017 affects users of IBM Controller versions 11.1.0 to 11.1.1 and IBM Cognos Controller versions 11.0.0 to 11.0.1 FP6.
What kind of data is exposed in CVE-2025-36017?
CVE-2025-36017 exposes sensitive information that is stored unencrypted in environmental variables.
Is there a patch available for CVE-2025-36017?
As of now, users are advised to implement security best practices as a patch for CVE-2025-36017 has not been officially released.