CVE-2025-36105
IBM Planning Analytics Advanced Certified Containers 3.1.0 through 3.1.4 could allow a local privileged user to obtain sensitive information from environment variables.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.4
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- EPSS probability
- 0.08%
- CWE
- CWE-526
- Published
- 2026-03-10
- Last modified
- 2026-03-10
Affected products
- IBM Planning Analytics Advanced Certified Containers
Weakness type
Related vulnerabilities
- CVE-2026-76227 — Renovate 42.68.1 before 42.96.3 Environment Variable Exposure
- CVE-2026-72648 — Cleartext Storage of Sensitive Information in an Environment Variable in Elastic Cloud on Kubernetes Leading to Information Disclosure
- CVE-2026-49377 — In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters
- CVE-2026-45370 — python-utcp: Full Process Environment Exposed to CLI Subprocess - Secrets Leakage via Command Injection
- CVE-2026-40153 — PraisonAIAgents Affected by Environment Variable Secret Exfiltration via os.path.expandvars() Bypassing shell=False in Shell Tool
- CVE-2025-27899 — Multiple vulnerabilities in IBM Java SDK affecting Db2 Recovery Expert for Linux, Unix and Windows
- CVE-2025-36017 — IBM Controller Information Disclosure
- CVE-2025-9162 — Org.keycloak/keycloak-model-storage-service: variable injection into environment variables