CVE-2025-36105
MEDIUMIBM Planning Analytics Advanced 3.1.0-3.1.4 - Info Disclosure
Title source: llmDescription
IBM Planning Analytics Advanced Certified Containers 3.1.0 through 3.1.4 could allow a local privileged user to obtain sensitive information from environment variables.
References (1)
Core 1
Core References
Various Sources vendor-advisory
patch
https://www.ibm.com/support/pages/node/7262806
Scores
CVSS v3
4.4
EPSS
0.0008
EPSS Percentile
0.3%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-312
CWE-526
Status
published
Products (1)
ibm/planning_analytics_advanced_certified_containers
3.1.0 - 3.1.5
Published
Mar 10, 2026
Tracked Since
Mar 10, 2026