CVE-2025-1350: Multiple vulnerabilities in IBM Controller
IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
Other sources
IBM Controller could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Cognos Controllerto a version that resolves this vulnerability.Fixed in 11.2 - Upgrade
Upgrade
IBM Cognos Controllerto a version that resolves this vulnerability.Fixed in 11.0.1 FP7 - Upgrade
Upgrade
IBM Cognos Controllerto a version that resolves this vulnerability.Fixed in 11.1.3 FP1 - Compensating control
Apply the most recent security updates for IBM Cognos Controller, since multiple vulnerabilities could be used in further attacks against the system.
Event History
Frequently Asked Questions
Which IBM Controller versions are affected?
Affected versions are IBM Controller 11.0.0 through 11.0.1 FP7 and 11.1.0 through 11.1.3 FP1.
Does exploitation require authentication or user interaction?
No. The listed vector indicates network-reachable exploitation with low attack complexity, no privileges required, and no user interaction required.
What is the impact of successful exploitation?
A remote attacker may obtain sensitive information exposed through detailed technical error messages returned in the browser. The disclosed information could support further attacks against the system.