MEDIUM🇵🇱 Wersja polska

CVE-2025-36057

CVSS 5.2v3.1pub. 2025-07-21upd. 2025-08-07

IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 is vulnerable to authentication bypass by using the Local Authentication Framework library which is not needed as biometric authentication is not used in the application.

CVSS Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
  • IBM Cognos Analytics Mobile

    APP
    Ibm
    1.1.0 – 1.1.23 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2025-36106MEDIUM6.5same product

IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 could allow malicious actors to view and modify informa...

CVE-2025-36062MEDIUM5.9same product

IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 could be vulnerable to information exposure due to th...

CVE-2025-36107MEDIUM5.9same product

IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 could allow malicious actors to obtain sensitive inform...

CVE-2021-39081MEDIUM5.9same product

IBM Cognos Analytics Mobile for Android 1.1.14 uses weaker than expected cryptographic algorithms that could a...

CVE-2021-39079MEDIUM5.4same product

IBM Cognos Analytics Mobile for Android applications prior to version 1.1.14 is vulnerable to cross-site scrip...