CVE-2025-33111

MEDIUM

IBM Controller <11.1.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 is vulnerable to creation of temporary files without atomic operations which may expose sensitive information to an authenticated user due to race condition attacks.

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory patch
https://www.ibm.com/support/pages/node/7253273

Scores

CVSS v3 4.3
EPSS 0.0003
EPSS Percentile 9.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-379
Status published
Products (2)
ibm/cognos_controller 11.0.0 - 11.0.1.7
ibm/controller 11.1.0 - 11.1.2
Published Dec 08, 2025
Tracked Since Feb 18, 2026