CVE Vulnerabilities

CVE-2025-0923

Inclusion of Sensitive Information in Source Code

Published: Jun 11, 2025 | Modified: Jun 17, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 stores source code on the web server that could aid in further attacks against the system.

Weakness

Source code on a web server or repository often contains sensitive information and should generally not be accessible to users.

Affected Software

Name Vendor Start Version End Version
Cognos_analytics Ibm 11.2.0 (including) 11.2.4 (including)
Cognos_analytics Ibm 12.0.0 (including) 12.0.4 (including)
Cognos_analytics Ibm 11.2.4-fixpack1 (including) 11.2.4-fixpack1 (including)
Cognos_analytics Ibm 11.2.4-fixpack2 (including) 11.2.4-fixpack2 (including)
Cognos_analytics Ibm 11.2.4-fixpack3 (including) 11.2.4-fixpack3 (including)

Potential Mitigations

References