CVE-2025-36017
IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 stores unencrypted sensitive information in environmental variables files which can be obtained by an authenticated user.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS probability
- 0.27%
- CWE
- CWE-526
- Published
- 2025-12-08
- Last modified
- 2026-03-13
Affected products
- IBM Controller
Weakness type
Related vulnerabilities
- CVE-2026-76227 — Renovate 42.68.1 before 42.96.3 Environment Variable Exposure
- CVE-2026-72648 — Cleartext Storage of Sensitive Information in an Environment Variable in Elastic Cloud on Kubernetes Leading to Information Disclosure
- CVE-2026-49377 — In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters
- CVE-2026-45370 — python-utcp: Full Process Environment Exposed to CLI Subprocess - Secrets Leakage via Command Injection
- CVE-2026-40153 — PraisonAIAgents Affected by Environment Variable Secret Exfiltration via os.path.expandvars() Bypassing shell=False in Shell Tool
- CVE-2025-36105 — IBM Planning Analytics Advanced Certified Containers is vulnerable to a sensitive information disclosure vulnerability
- CVE-2025-27899 — Multiple vulnerabilities in IBM Java SDK affecting Db2 Recovery Expert for Linux, Unix and Windows
- CVE-2025-9162 — Org.keycloak/keycloak-model-storage-service: variable injection into environment variables