{"api_version":"1","generated_at":"2026-10-01T21:11:48+00:00","cve":"CVE-2025-36076","urls":{"html":"https://cve.report/CVE-2025-36076","api":"https://cve.report/api/cve/CVE-2025-36076.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2025-36076","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2025-36076"},"summary":{"title":"IBM Cognos Analytics versions 12.0.4 and 12.1.3 is affected by security vulnerabilities","description":"IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 stores sensitive information in source code could be used by an authenticated user in further attacks against the system.","state":"PUBLISHED","assigner":"ibm","published_at":"2026-09-18 16:17:02","updated_at":"2026-09-18 18:17:47"},"problem_types":["CWE-540","CWE-540 CWE-540 Inclusion of Sensitive Information in Source Code"],"metrics":[{"version":"3.1","source":"psirt@us.ibm.com","type":"Secondary","score":"4.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"4.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","version":"3.1"}}],"references":[{"url":"https://www.ibm.com/support/pages/node/7287209","name":"https://www.ibm.com/support/pages/node/7287209","refsource":"psirt@us.ibm.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-36076","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-36076","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"IBM","product":"Cognos Analytics","version":"affected 12.1.0 12.1.3 FP1 semver","platforms":[]},{"source":"CNA","vendor":"IBM","product":"Cognos Analytics","version":"affected 12.0.4 12.0.4 FP2 semver","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"IBM strongly recommends addressing the vulnerability now.\n\nAffected Product(s)Version(s)Fix VersionIBM Cognos Analytics12.1.0, 12.1.1, 12.1.2, 12.1.3, 12.1.3 FP1 12.1.3 FP2 https://www.ibm.com/support/pages/node/7283969 IBM Cognos Analytics12.0.4 - 12.0.4 FP2 12.0.4 FP3 https://www.ibm.com/support/pages/node/7269268","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2025","cve_id":"36076","cve":"CVE-2025-36076","epss":"0.002950000","percentile":"0.222840000","score_date":"2026-09-21","updated_at":"2026-09-22 00:03:18"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2025-36076","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-09-18T16:44:54.712593Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-09-18T16:45:07.526Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"cpes":["cpe:2.3:a:ibm:cognos_analytics:12.1.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:cognos_analytics:12.1.3:*:*:*:*:*:*:*","cpe:2.3:a:ibm:cognos_analytics:12.0.4:*:*:*:*:*:*:*"],"product":"Cognos Analytics","vendor":"IBM","versions":[{"lessThanOrEqual":"12.1.3 FP1","status":"affected","version":"12.1.0","versionType":"semver"},{"lessThanOrEqual":"12.0.4 FP2","status":"affected","version":"12.0.4","versionType":"semver"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 stores sensitive information in source code could be used by an authenticated user in further attacks against the system.</p>"}],"value":"IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 stores sensitive information in source code could be used by an authenticated user in further attacks against the system."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-540","description":"CWE-540 Inclusion of Sensitive Information in Source Code","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-18T15:41:19.901Z","orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm"},"references":[{"tags":["vendor-advisory","patch"],"url":"https://www.ibm.com/support/pages/node/7287209"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>IBM strongly recommends addressing the vulnerability now.</p><div><table><colgroup><col/><col/><col/></colgroup><tbody><tr><td>Affected Product(s)</td><td>Version(s)</td><td>Fix Version</td></tr><tr><td>IBM Cognos Analytics</td><td>12.1.0, 12.1.1, 12.1.2, 12.1.3, 12.1.3 FP1</td><td><a href=\"https://www.ibm.com/support/pages/node/7283969\" rel=\"nofollow\">12.1.3 FP2</a></td></tr><tr><td>IBM Cognos Analytics</td><td>12.0.4 - 12.0.4 FP2</td><td><a href=\"https://www.ibm.com/support/pages/node/7269268\" rel=\"nofollow\">12.0.4 FP3</a></td></tr><tr><td></td><td></td><td></td></tr></tbody></table></div>"}],"value":"IBM strongly recommends addressing the vulnerability now.\n\nAffected Product(s)Version(s)Fix VersionIBM Cognos Analytics12.1.0, 12.1.1, 12.1.2, 12.1.3, 12.1.3 FP1 12.1.3 FP2 https://www.ibm.com/support/pages/node/7283969 IBM Cognos Analytics12.0.4 - 12.0.4 FP2 12.0.4 FP3 https://www.ibm.com/support/pages/node/7269268"}],"title":"IBM Cognos Analytics versions 12.0.4 and 12.1.3 is affected by security vulnerabilities"}},"cveMetadata":{"assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","assignerShortName":"ibm","cveId":"CVE-2025-36076","datePublished":"2026-09-18T15:41:19.901Z","dateReserved":"2025-04-15T21:16:13.122Z","dateUpdated":"2026-09-18T16:45:07.526Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-18 16:17:02","lastModifiedDate":"2026-09-18 18:17:47","problem_types":["CWE-540","CWE-540 CWE-540 Inclusion of Sensitive Information in Source Code"],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-18T16:44:54.712593Z","id":"CVE-2025-36076","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2025","CveId":"36076","Ordinal":"1","Title":"IBM Cognos Analytics versions 12.0.4 and 12.1.3 is affected by s","CVE":"CVE-2025-36076","Year":"2025"},"notes":[{"CveYear":"2025","CveId":"36076","Ordinal":"1","NoteData":"IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 stores sensitive information in source code could be used by an authenticated user in further attacks against the system.","Type":"Description","Title":"IBM Cognos Analytics versions 12.0.4 and 12.1.3 is affected by s"}]}}}