CVE Vulnerabilities

CVE-2025-36017

Cleartext Storage of Sensitive Information in an Environment Variable

Published: Dec 08, 2025 | Modified: Dec 10, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 stores unencrypted sensitive information in environmental variables files which can be obtained by an authenticated user.

Weakness

The product uses an environment variable to store unencrypted sensitive information.

Affected Software

Name Vendor Start Version End Version
Controller Ibm 11.1.0 (including) 11.1.2 (excluding)

Potential Mitigations

References