{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2025-36421","assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","state":"PUBLISHED","assignerShortName":"ibm","dateReserved":"2025-04-15T21:17:02.754Z","datePublished":"2026-09-18T15:44:27.068Z","dateUpdated":"2026-09-19T14:21:50.487Z"},"containers":{"cna":{"providerMetadata":{"orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm","dateUpdated":"2026-09-18T15:44:27.068Z"},"title":"Multiple vulnerabilities in IBM Controller","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-319","description":"CWE-319 Cleartext Transmission of Sensitive Information","type":"CWE"}]}],"affected":[{"vendor":"IBM","product":"Controller","versions":[{"status":"affected","version":"11.0.0","lessThanOrEqual":"11.0.1 FP7","versionType":"semver"},{"status":"affected","version":"11.1.0","lessThanOrEqual":"11.1.3 FP1","versionType":"semver"}],"cpes":["cpe:2.3:a:ibm:controller:11.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:controller:11.0.1:*:*:*:*:*:*:*","cpe:2.3:a:ibm:controller:11.1.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:controller:11.1.3:*:*:*:*:*:*:*"]}],"descriptions":[{"lang":"en","value":"IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.</p>"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7287970","tags":["vendor-advisory","patch"]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseSeverity":"MEDIUM","baseScore":5.9,"vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"}}],"solutions":[{"lang":"en","value":"It is strongly recommended that you apply the most recent security updates:\n\n\n\n\n\n\n\nAffected Product(s)Version(s)FixIBM Cognos Controller11.0.0 - 11.0.1 FP7 https://www.ibm.com/mysupport . Customers currently running IBM Controller 11.0 and 11.1 can upgrade to the 11.2 release stream at no additional charge.","supportingMedia":[{"type":"text/html","base64":false,"value":"<div><div><div><div>It is strongly recommended that you apply the most recent security updates:</div></div></div></div><div><table><tbody><tr><td><strong>Affected Product(s)</strong></td><td><strong>Version(s)</strong></td><td><strong>Fix</strong></td></tr><tr><td>IBM Cognos Controller</td><td>11.0.0 - 11.0.1 FP7</td><td><a href=\"https://www.ibm.com/software/passportadvantage/pao-customer\" rel=\"nofollow\">Download IBM Controller 11.1.0 from Passport Advantage</a></td></tr><tr><td>IBM Controller</td><td>11.1.0 - 11.1.3 FP1</td><td><a href=\"https://www.ibm.com/software/passportadvantage/pao-customer\" rel=\"nofollow\">Download IBM Controller 11.2.0 from Passport Advantage</a></td></tr></tbody></table></div><p><br/>IBM Controller 11.2.0  is available for Cloud deployments. To schedule an upgrade to this release for either your non-production or production environment, log a support case at <a href=\"https://www.ibm.com/mysupport\" rel=\"nofollow\">https://www.ibm.com/mysupport</a>. Customers currently running IBM Controller 11.0 and 11.1 can upgrade to the 11.2 release stream at no additional charge.<br/></p>"}]}]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"id":"CVE-2025-36421","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"version":"2.0.3","timestamp":"2026-09-19T13:45:03.739556Z"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-19T14:21:50.487Z"}}]}}