CVE-2025-36326
BaseFortify
Publication date: 2025-09-26
Last updated on: 2025-10-03
Assigner: IBM Corporation
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ibm | cognos_controller | From 11.0.0 (inc) to 11.0.1 (inc) |
| ibm | controller | From 11.1.0 (inc) to 11.1.1 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-321 | The product uses a hard-coded, unchangeable cryptographic key. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in IBM Cognos Controller versions 11.0.0 through 11.0.1 and IBM Controller versions 11.1.0 through 11.1.1. It allows an attacker to obtain sensitive information because the software uses hardcoded cryptographic keys to sign session cookies. Hardcoded keys can be discovered and exploited, compromising the security of session management.
How can this vulnerability impact me? :
An attacker exploiting this vulnerability could obtain sensitive information by leveraging the hardcoded cryptographic keys used for signing session cookies. This could lead to unauthorized access to user sessions or data, potentially compromising confidentiality.