CVE-2025-36057
IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 is vulnerable to authentication bypass by using the Local Authentication Framework library which is not needed as biometric authentication is not used in the application.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.2
- CVSS vector
- CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
- EPSS probability
- 0.18%
- CWE
- CWE-299
- Published
- 2025-07-21
- Last modified
- 2026-03-13
Affected products
- IBM Cognos Analytics Mobile
Weakness type
Related vulnerabilities
- CVE-2026-86231 — mwiede jsch KnownHosts.java getRevokedKeys improper check for certificate revocation
- CVE-2026-61699 — nebula-mesh: Certificate revocation is never enforced at the mesh
- CVE-2026-56821 — Netty: Out-of-date OCSP Responses Accepted by OcspServerCertificateValidator
- CVE-2026-9636 — Rockwell Automation CompactLogix® 5380 ControlLogix® 5580 / 1756-EN4 Communications Module – Certificate Revocation List Vulnerability
- CVE-2026-6899 — Improper Check for Certificate Revocation in S2OPC
- CVE-2026-4428 — CRL Distribution Point Scope Check Logic Error in AWS-LC
- CVE-2025-11955 — Incorrect validation of OCSP certificates in TheGreenBow VPN Client Windows Enterprise
- CVE-2025-3085 — MongoDB Server running on Linux may allow unexpected connections where intermediate certificates are revoked