IBM Controller 11.0.0, 11.0.1, and 11.1.0 application could allow an authenticated user to obtain sensitive credentials that may be inadvertently included within the source code.
The product stores a password in plaintext within resources such as memory or files.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Cognos_controller | Ibm | 11.0.0 (including) | 11.0.0 (including) |
| Cognos_controller | Ibm | 11.0.1 (including) | 11.0.1 (including) |
| Controller | Ibm | 11.1.0 (including) | 11.1.0 (including) |