CVE-2025-36102: IBM Controller Validation Bypass
IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 could allow a privileged user to bypass validation, passing user input into the application as trusted data, due to client-side enforcement of server-side security.
Other sources
IBM Controller could allow a privileged user to bypass validation, passing user input into the application as trusted data, due to client-side enforcement of server-side security.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36102?
CVE-2025-36102 is classified as a medium severity vulnerability.
How do I fix CVE-2025-36102?
To mitigate CVE-2025-36102, upgrade to IBM Controller version 11.1.2 or later and IBM Cognos Controller version 11.0.2 or later.
Who is affected by CVE-2025-36102?
CVE-2025-36102 affects users of IBM Controller versions 11.1.0 through 11.1.1 and IBM Cognos Controller versions 11.0.0 through 11.0.1 FP6.
What type of vulnerability is CVE-2025-36102?
CVE-2025-36102 is a client-side enforcement vulnerability that allows a privileged user to bypass validation.
What impact does CVE-2025-36102 have?
The impact of CVE-2025-36102 is that it allows attackers to pass unvalidated user input into the application, potentially compromising security.