CVE-2025-36187

MEDIUM

Multiple Security vulnerabilities affecting IBM Knowledge Catalog Standard Cartridge

Title source: cna
STIX 2.1

Description

IBM Knowledge Catalog Standard Cartridge 5.0.0, 5.0.1, 5.0.2, 5.0.3, 5.1, 5.1.1, 5,1.2, 5.1.3, 5.2.0, 5.2.1 stores potentially sensitive information in log files that could be read by a local privileged user.

Scores

CVSS v3 4.4
EPSS 0.0001
EPSS Percentile 3.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-532
Status published
Products (11)
IBM/Knowledge Catalog Standard Cartridge 5.0.0, 5.0.1, 5.0.2, 5.0.3, 5.1, 5.1.1, 5,1.2, 5.1.3, 5.2.0, 5.2.1
ibm/knowledge_catalog 5.0.0
ibm/knowledge_catalog 5.0.1
ibm/knowledge_catalog 5.0.2
ibm/knowledge_catalog 5.0.3
ibm/knowledge_catalog 5.1
ibm/knowledge_catalog 5.1.1
ibm/knowledge_catalog 5.1.2
ibm/knowledge_catalog 5.1.3
ibm/knowledge_catalog 5.2.0
... and 1 more
Published Mar 25, 2026
Tracked Since Mar 26, 2026