CVE-2025-33079: IBM Controller information disclosure
IBM Controller 11.0.0, 11.0.1, and 11.1.0 application could allow an authenticated user to obtain sensitive credentials that may be inadvertently included within the source code.
Other sources
IBM Controller application could allow an authenticated user to obtain sensitive credentials that may be inadvertently included within the source code.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-33079?
CVE-2025-33079 has been classified as a potential security vulnerability that may lead to exposure of sensitive credentials.
How do I fix CVE-2025-33079?
To fix CVE-2025-33079, review your source code to ensure sensitive credentials are not exposed and update IBM Controller to the latest version.
Who is affected by CVE-2025-33079?
CVE-2025-33079 affects authenticated users of IBM Controller versions 11.0.0, 11.0.1, and 11.1.0.
What type of vulnerability is CVE-2025-33079?
CVE-2025-33079 is a vulnerability that allows an authenticated user to access sensitive credentials inadvertently included in the source code.
Is there a workaround for CVE-2025-33079?
While a direct workaround is not specified, ensure that sensitive information is not embedded in your application's source code to mitigate risks associated with CVE-2025-33079.