CVE-2025-36421

Summary

IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.

Affected Software

VendorProductVersion RangeStatus
IBMController11.0.0 <= 11.0.1 FP7affected
IBMController11.1.0 <= 11.1.3 FP1affected

Weaknesses

  • CWE-319: CWE-319 Cleartext Transmission of Sensitive Information

References