CVE-2025-36015: IBM Cognos Controller

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 could allow an authenticated user to cause a denial of service due to improper validation of a specified quantity size input.

Affected products

  • IBM Cognos Controller: from 11.0.0, before 11.0.1.7 (fixed in 11.0.1.7)
  • IBM Controller: from 11.1.0, before 11.1.2 (fixed in 11.1.2)

Published 2025-12-08. Last modified 2026-10-07.