{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2025-36076","assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","state":"PUBLISHED","assignerShortName":"ibm","dateReserved":"2025-04-15T21:16:13.122Z","datePublished":"2026-09-18T15:41:19.901Z","dateUpdated":"2026-09-18T16:45:07.526Z"},"containers":{"cna":{"providerMetadata":{"orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm","dateUpdated":"2026-09-18T15:41:19.901Z"},"title":"IBM Cognos Analytics versions 12.0.4 and 12.1.3 is affected by security vulnerabilities","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-540","description":"CWE-540 Inclusion of Sensitive Information in Source Code","type":"CWE"}]}],"affected":[{"vendor":"IBM","product":"Cognos Analytics","versions":[{"status":"affected","version":"12.1.0","lessThanOrEqual":"12.1.3 FP1","versionType":"semver"},{"status":"affected","version":"12.0.4","lessThanOrEqual":"12.0.4 FP2","versionType":"semver"}],"cpes":["cpe:2.3:a:ibm:cognos_analytics:12.1.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:cognos_analytics:12.1.3:*:*:*:*:*:*:*","cpe:2.3:a:ibm:cognos_analytics:12.0.4:*:*:*:*:*:*:*"]}],"descriptions":[{"lang":"en","value":"IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 stores sensitive information in source code could be used by an authenticated user in further attacks against the system.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 stores sensitive information in source code could be used by an authenticated user in further attacks against the system.</p>"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7287209","tags":["vendor-advisory","patch"]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseSeverity":"MEDIUM","baseScore":4.3,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"}}],"solutions":[{"lang":"en","value":"IBM strongly recommends addressing the vulnerability now.\n\nAffected Product(s)Version(s)Fix VersionIBM Cognos Analytics12.1.0, 12.1.1, 12.1.2, 12.1.3, 12.1.3 FP1 12.1.3 FP2 https://www.ibm.com/support/pages/node/7283969 IBM Cognos Analytics12.0.4 - 12.0.4 FP2 12.0.4 FP3 https://www.ibm.com/support/pages/node/7269268","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>IBM strongly recommends addressing the vulnerability now.</p><div><table><colgroup><col/><col/><col/></colgroup><tbody><tr><td>Affected Product(s)</td><td>Version(s)</td><td>Fix Version</td></tr><tr><td>IBM Cognos Analytics</td><td>12.1.0, 12.1.1, 12.1.2, 12.1.3, 12.1.3 FP1</td><td><a href=\"https://www.ibm.com/support/pages/node/7283969\" rel=\"nofollow\">12.1.3 FP2</a></td></tr><tr><td>IBM Cognos Analytics</td><td>12.0.4 - 12.0.4 FP2</td><td><a href=\"https://www.ibm.com/support/pages/node/7269268\" rel=\"nofollow\">12.0.4 FP3</a></td></tr><tr><td></td><td></td><td></td></tr></tbody></table></div>"}]}]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-18T16:44:54.712593Z","id":"CVE-2025-36076","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-18T16:45:07.526Z"}}]}}