CVE Vulnerabilities

CVE-2025-33079

Plaintext Storage of a Password

Published: May 27, 2025 | Modified: Jun 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM Controller 11.0.0, 11.0.1, and 11.1.0 application could allow an authenticated user to obtain sensitive credentials that may be inadvertently included within the source code.

Weakness

The product stores a password in plaintext within resources such as memory or files.

Affected Software

NameVendorStart VersionEnd Version
Cognos_controllerIbm11.0.0 (including)11.0.0 (including)
Cognos_controllerIbm11.0.1 (including)11.0.1 (including)
ControllerIbm11.1.0 (including)11.1.0 (including)

Potential Mitigations

References