IBM Cognos Controller Cryptographic Weakness Leading to Decryption of Sensitive Information Vulnerability

Vulnerability

A vulnerability exists in IBM Cognos Controller versions 11.0.0 to 11.0.1 FP3 and in the IBM Controller 11.1.0 Rich Client. These versions utilize cryptographic algorithms that are weaker than expected, potentially allowing an attacker to decrypt highly sensitive information.

Impact

Exploitation of this vulnerability could lead to the unauthorized decryption of sensitive information.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
2.5
exploitability
7.0
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.