Ibm Controller vulnerabilities
20 known vulnerabilities affecting ibm/controller.
Total CVEs
20
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH6MEDIUM12LOW2
Vulnerabilities
Page 1 of 1
CVE-2025-33111MEDIUMCVSS 4.3≥ 11.1.0, < 11.1.2≥ 11.1.0, ≤ 11.1.12025-12-08
CVE-2025-33111 [MEDIUM] CWE-379 CVE-2025-33111: IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 is vulnerab
IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 is vulnerable to creation of temporary files without atomic operations which may expose sensitive information to an authenticated user due to race condition attacks.
cvelistv5nvd
CVE-2025-36015MEDIUMCVSS 6.5≥ 11.1.0, < 11.1.2≥ 11.1.0, ≤ 11.1.12025-12-08
CVE-2025-36015 [MEDIUM] CWE-1284 CVE-2025-36015: IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 could allow
IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 could allow an authenticated user to cause a denial of service due to improper validation of a specified quantity size input.
cvelistv5nvd
CVE-2025-36017MEDIUMCVSS 6.5≥ 11.1.0, < 11.1.2≥ 11.1.0, ≤ 11.1.12025-12-08
CVE-2025-36017 [MEDIUM] CWE-526 CVE-2025-36017: IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 stores unen
IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 stores unencrypted sensitive information in environmental variables files which can be obtained by an authenticated user.
cvelistv5nvd
CVE-2025-36102LOWCVSS 2.7≥ 11.1.0, < 11.1.2≥ 11.1.0, ≤ 11.1.12025-12-08
CVE-2025-36102 [LOW] CWE-602 CVE-2025-36102: IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 could allow
IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 could allow a privileged user to bypass validation, passing user input into the application as trusted data, due to client-side enforcement of server-side security.
cvelistv5nvd
CVE-2025-36326HIGHCVSS 7.5≥ 11.1.0, ≤ 11.1.12025-09-26
CVE-2025-36326 [LOW] CWE-321 CVE-2025-36326: IBM Cognos Controller 11.0.0 through 11.0.1, and IBM Controller 11.1.0 through 11.1.1 could allow an
IBM Cognos Controller 11.0.0 through 11.0.1, and IBM Controller 11.1.0 through 11.1.1 could allow an attacker to obtain sensitive information due to the use of hardcoded cryptographic keys for signing session cookies.
cvelistv5nvd
CVE-2025-33079MEDIUMCVSS 6.5v11.1.02025-05-27
CVE-2025-33079 [MEDIUM] CWE-256 CVE-2025-33079: IBM Controller 11.0.0, 11.0.1, and 11.1.0 application could allow an authenticated user to obtain se
IBM Controller 11.0.0, 11.0.1, and 11.1.0 application could allow an authenticated user to obtain sensitive credentials that may be inadvertently included within the source code.
cvelistv5nvd
CVE-2022-39163MEDIUMCVSS 4.7v11.1.02025-03-26
CVE-2022-39163 [MEDIUM] CWE-444 CVE-2022-39163: IBM Cognos Controller 11.0.0 through 11.1.0 is vulnerable to a Client-Side Desync (CSD) attack where
IBM Cognos Controller 11.0.0 through 11.1.0 is vulnerable to a Client-Side Desync (CSD) attack where an attacker could exploit a desynchronized browser connection that could lead to further cross-site scripting (XSS) attacks.
cvelistv5nvd
CVE-2024-41778MEDIUMCVSS 6.5v11.0.0v11.0.1+2 more2025-03-01
CVE-2024-41778 [MEDIUM] CWE-521 CVE-2024-41778: IBM Controller 11.0.0 through 11.0.1 and 11.1.0 does not require that users should have strong passw
IBM Controller 11.0.0 through 11.0.1 and 11.1.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
cvelistv5nvd
CVE-2023-47160HIGHCVSS 8.2v11.1.02025-02-19
CVE-2023-47160 [HIGH] CWE-611 CVE-2023-47160: IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0
is vulnerable to an
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0
is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
cvelistv5nvd
CVE-2024-52902HIGHCVSS 8.8v11.1.02025-02-19
CVE-2024-52902 [HIGH] CWE-798 CVE-2024-52902: IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 client application contain
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 client application contains hard coded database passwords in source code which could be used for unauthorized access to the system.
cvelistv5nvd
CVE-2024-45084HIGHCVSS 8.0v11.1.02025-02-19
CVE-2024-45084 [HIGH] CWE-1236 CVE-2024-45084: IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0
could allow an authentic
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0
could allow an authenticated attacker to conduct formula injection. An attacker could execute arbitrary commands on the system, caused by improper validation of file contents.
cvelistv5nvd
CVE-2024-28777HIGHCVSS 8.8v11.1.02025-02-19
CVE-2024-28777 [HIGH] CWE-502 CVE-2024-28777: IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0
is vulnerable to unres
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0
is vulnerable to unrestricted deserialization. This vulnerability allows users to execute arbitrary code, escalate privileges, or cause denial of service attacks by exploiting the unrestricted deserialization of types in the application.
cvelistv5nvd
CVE-2024-28780MEDIUMCVSS 5.9v11.1.02025-02-19
CVE-2024-28780 [MEDIUM] CWE-327 CVE-2024-28780: IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 Rich Client
uses wea
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 Rich Client
uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
cvelistv5nvd
CVE-2024-45081MEDIUMCVSS 6.5v11.1.02025-02-19
CVE-2024-45081 [MEDIUM] CWE-863 CVE-2024-45081: IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0
could allow an authent
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0
could allow an authenticated user to modify restricted content due to incorrect authorization checks.
cvelistv5nvd
CVE-2024-28776MEDIUMCVSS 5.4v11.1.02025-02-19
CVE-2024-28776 [MEDIUM] CWE-79 CVE-2024-28776: IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0
is vulnerable to cross-s
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0
is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
cvelistv5nvd
CVE-2024-40702HIGHCVSS 8.2v11.1.02025-01-07
CVE-2024-40702 [HIGH] CWE-295 CVE-2024-40702: IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow an unauthorized us
IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow an unauthorized user to obtain valid tokens to gain access to protected resources due to improper certificate validation.
cvelistv5nvd
CVE-2024-25037MEDIUMCVSS 4.3v11.1.02025-01-07
CVE-2024-25037 [MEDIUM] CWE-209 CVE-2024-25037: IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow a remote attacker
IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser.
cvelistv5nvd
CVE-2024-28778MEDIUMCVSS 6.5v11.1.02025-01-07
CVE-2024-28778 [MEDIUM] CWE-798 CVE-2024-28778: IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 is vulnerable to exposure of A
IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 is vulnerable to exposure of Artifactory API keys. This vulnerability allows users to publish code to private packages or repositories under the name of the organization.
cvelistv5nvd
CVE-2022-22363MEDIUMCVSS 4.3v11.1.02025-01-07
CVE-2022-22363 [MEDIUM] CWE-209 CVE-2022-22363: IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow a remote attacker
IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
cvelistv5nvd
CVE-2021-20455LOWCVSS 3.7v11.1.02025-01-07
CVE-2021-20455 [LOW] CWE-209 CVE-2021-20455: IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow a remote attacker
IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
cvelistv5nvd