CVE-2025-36102: IBM Cognos Controller

Low severity, CVSS 2.7. EPSS: 0.2% chance of exploitation in the next 30 days.

IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 could allow a privileged user to bypass validation, passing user input into the application as trusted data, due to client-side enforcement of server-side security.

Affected products

  • IBM Cognos Controller: from 11.0.0, before 11.0.1.7 (fixed in 11.0.1.7)
  • IBM Controller: from 11.1.0, before 11.1.2 (fixed in 11.1.2)

Published 2025-12-08. Last modified 2026-10-07.