IBM Controller 11.0.0, 11.0.1, and 11.1.0 application could allow an authenticated user to obtain sensitive credentials that may be inadvertently included within the source code.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-27838 IBM Controller 11.0.0, 11.0.1, and 11.1.0 application could allow an authenticated user to obtain sensitive credentials that may be inadvertently included within the source code.
Fixes

Solution

It is strongly recommended that you apply the most recent security updates: IBM Controller 11.1.0 FP4 from Fix Central IBM Cognos Controller 11.0.1 FP5 from Fix Central


Workaround

No workaround given by the vendor.

History

Tue, 10 Jun 2025 04:15:00 +0900

Type Values Removed Values Added
First Time appeared Ibm cognos Controller
Weaknesses CWE-522
CPEs cpe:2.3:a:ibm:cognos_controller:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_controller:11.0.1:*:*:*:*:*:*:*
Vendors & Products Ibm cognos Controller

Wed, 28 May 2025 05:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 27 May 2025 10:45:00 +0900

Type Values Removed Values Added
Description IBM Controller 11.0.0, 11.0.1, and 11.1.0 application could allow an authenticated user to obtain sensitive credentials that may be inadvertently included within the source code.
Title IBM Controller information disclosure
First Time appeared Ibm
Ibm controller
Weaknesses CWE-256
CPEs cpe:2.3:a:ibm:controller:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:controller:11.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:controller:11.1.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm controller
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2025-08-26T15:03:51.764Z

Reserved: 2025-04-15T17:50:20.368Z

Link: CVE-2025-33079

cve-icon Vulnrichment

Updated: 2025-05-27T19:37:11.644Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-27T02:15:19.393

Modified: 2025-06-09T18:49:31.260

Link: CVE-2025-33079

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses