CVE-2025-36178

Summary

IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 could allow an authenticated user to bypass input validation due to improper validation of client-side input of file size.

Affected Software

VendorProductVersion RangeStatus
IBMController11.0.0 <= 11.0.1 FP7affected
IBMController11.1.0 <= 11.1.3 FP1affected

Weaknesses

  • CWE-1284: CWE-1284 Improper Validation of Specified Quantity in Input

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References