CVE-2025-36076: IBM Cognos Analytics versions 12.0.4 and 12.1.3 is affected by security vulnerabilities
IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 stores sensitive information in source code could be used by an authenticated user in further attacks against the system.
Other sources
IBM Cognos Analytics stores sensitive information in source code could be used by an authenticated user in further attacks against the system.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Cognos Analyticsto a version that resolves this vulnerability.Fixed in 12.1.3 FP2 - Upgrade
Upgrade
IBM Cognos Analyticsto a version that resolves this vulnerability.Fixed in 12.0.4 FP3
Event History
Frequently Asked Questions
What level of access would an attacker need?
An attacker would need to be authenticated to IBM Cognos Analytics. The issue could then be used in further attacks against the system.
What is exposed by this issue?
Sensitive information is stored in source code. The provided information does not identify the specific data involved or where in the product it is exposed.