cbcvebase.
CVE-2025-36102
published 2025-12-08

CVE-2025-36102: IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 could allow a privileged user to bypass validation, passing user input…

low2.7CVSS 3.1
AVNACLPRHUINSUCNILAN
IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 could allow a privileged user to bypass validation, passing user input into the application as trusted data, due to client-side enforcement of server-side security.

Affected

4 ranges
VendorProductVersion rangeFixed in
ibmcognos_controller>= 11.0.0 < 11.0.1.711.0.1.7
ibmcognos_controller11.0.0 – 11.0.1 FP6
ibmcontroller>= 11.1.0 < 11.1.211.1.2
ibmcontroller11.1.0 – 11.1.1