CVE-2024-25037: IBM Cognos Controller

Medium severity, CVSS 4.3. EPSS: 0.6% chance of exploitation in the next 30 days.

IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser.

Affected products

  • IBM Cognos Controller: from 11.0.0, up to and including 11.0.1
  • IBM Controller: version 11.1.0 only

Published 2025-01-07. Last modified 2026-06-17.