CVE-2025-36421: IBM Controller vulnerability
Published Sep 17, 2026
·Updated
IBM Controller transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.
Affected Software
2 affected components
IBM Controller<=11.0.0 - 11.0.1 FP7
IBM Controller<=11.1.0 - 11.1.3 FP1
Event History
Sep 17, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What access or network position would an attacker need to exploit this issue?
An attacker would need a man-in-the-middle position on the communication path in order to intercept data transmitted in clear text.
2
What could an attacker obtain if exploitation succeeds?
The issue could allow an attacker to obtain sensitive information from data transmitted without encryption.