« Volver al listado

CVE-2025-33079

Estado: AnalizadaMedia (6.5)—

IBM Controller 11.0.0, 11.0.1, and 11.1.0 application could allow an authenticated user to obtain sensitive credentials that may be inadvertently included within the source code.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-33079",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-33079",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-05-27T19:36:56.538109Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@us.ibm.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@us.ibm.com",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:ibm:controller:11.0.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:controller:11.0.1:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:controller:11.1.0:*:*:*:*:*:*:*"
          ],
          "vendor": "IBM",
          "product": "Controller",
          "versions": [
            {
              "status": "affected",
              "version": "11.1.0"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "IBM",
          "product": "Cognos Controller",
          "versions": [
            {
              "status": "affected",
              "version": "11.0.0, 11.0.1"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-05-27T02:15:19.393",
  "references": [
    {
      "url": "https://www.ibm.com/support/pages/node/7234720",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@us.ibm.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@us.ibm.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-256"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-522"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "IBM Controller 11.0.0, 11.0.1, and 11.1.0 application could allow an authenticated user to obtain sensitive credentials that may be inadvertently included within the source code."
    },
    {
      "lang": "es",
      "value": "La aplicación IBM Controller 11.0.0, 11.0.1 y 11.1.0 podría permitir que un usuario autenticado obtenga credenciales confidenciales que podrían estar incluidas inadvertidamente en el código fuente."
    }
  ],
  "lastModified": "2026-06-17T09:13:04.923",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ibm:cognos_controller:11.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4BB85020-BF02-4C91-B494-93FB19185006"
            },
            {
              "criteria": "cpe:2.3:a:ibm:cognos_controller:11.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "14DFBD62-8263-4F2F-90C5-A4A508E43B79"
            },
            {
              "criteria": "cpe:2.3:a:ibm:controller:11.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4DB99931-249F-4650-9612-B96803DEE909"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@us.ibm.com"
}