# CVE-2025-0923

## Summary

- **CVE ID:** CVE-2025-0923
- **Severity:** MEDIUM
- **CVSS Score:** 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
- **CWE:** CWE-540
- **Published:** Jun 11, 2025
- **Last Modified:** Mar 13, 2026

## Description

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 stores source code on the web server that could aid in further attacks against the system.

## Affected Products

- IBM — Cognos Analytics (11.2.0)
- IBM — Cognos Analytics (11.2.1)
- IBM — Cognos Analytics (11.2.2)
- IBM — Cognos Analytics (11.2.3)
- IBM — Cognos Analytics (11.2.4)
- IBM — Cognos Analytics (12.0.0)
- IBM — Cognos Analytics (12.0.1)
- IBM — Cognos Analytics (12.0.2)
- IBM — Cognos Analytics (12.0.3)
- IBM — Cognos Analytics (12.0.4)

## References

- [CNA](https://www.ibm.com/support/pages/node/7234674)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.26%
- **EPSS Percentile:** 18.1

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._