CVE Vulnerabilities

CVE-2025-0923

Inclusion of Sensitive Information in Source Code

Published: Jun 11, 2025 | Modified: Jun 17, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 stores source code on the web server that could aid in further attacks against the system.

Weakness

Source code on a web server or repository often contains sensitive information and should generally not be accessible to users.

Affected Software

NameVendorStart VersionEnd Version
Cognos_analyticsIbm11.2.0 (including)11.2.4 (including)
Cognos_analyticsIbm12.0.0 (including)12.0.4 (including)
Cognos_analyticsIbm11.2.4-fixpack1 (including)11.2.4-fixpack1 (including)
Cognos_analyticsIbm11.2.4-fixpack2 (including)11.2.4-fixpack2 (including)
Cognos_analyticsIbm11.2.4-fixpack3 (including)11.2.4-fixpack3 (including)

Potential Mitigations

References