CVE-2025-33079: IBM Cognos Controller

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

IBM Controller 11.0.0, 11.0.1, and 11.1.0 application could allow an authenticated user to obtain sensitive credentials that may be inadvertently included within the source code.

Affected products

  • IBM Cognos Controller: version 11.0.0 only; version 11.0.1 only
  • IBM Controller: version 11.1.0 only

Published 2025-05-27. Last modified 2026-06-17.