IBM Cognos Controller and IBM Controller Formula Injection Vulnerability Allowing Arbitrary Command Execution

Vulnerability

A formula injection vulnerability has been identified in IBM Cognos Controller versions 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0. This vulnerability could enable an authenticated attacker to execute arbitrary commands on the system, stemming from inadequate validation of file contents.

Impact

Exploitation of this vulnerability could lead to unauthorized command execution on the affected system.

Remediation

Users are advised to upgrade to IBM Cognos Controller 11.0.1 FP4 or IBM Controller 11.1.0.1. Instructions for downloading these versions are available on Fix Central.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
10.0
exploitability
4.9
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.