Unprotected storage of credentials in IBM Cognos Controller - CVE-2025-33079

 

Unprotected storage of credentials in IBM Cognos Controller - CVE-2025-33079

Published: May 27, 2025


Vulnerability identifier: #VU109856
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-33079
CWE-ID: CWE-256
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain access to other users' credentials.

The vulnerability exists due to application stored credentials in plain text in a configuration file on the system. A remote user can view contents of the configuration file and obtain sensitive credentials that may be inadvertently included within the source code.


Affected software

IBM Cognos Controller

How to mitigate CVE-2025-33079

Install updates from vendor's website.

IBM Cognos Controller - addressed in versions 11.0.1.5, 11.1.0.4

External References

Related Security Bulletins