MEDIUM🇵🇱 Wersja polska

CVE-2025-36106

CVSS 6.5v3.1pub. 2025-07-21upd. 2025-08-07

IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 could allow malicious actors to view and modify information coming to and from the application which could then be used to access confidential information on the device or network by using a the deprecated or misconfigured AFNetworking library at runtime.

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
  • IBM Cognos Analytics Mobile

    APP
    Ibm
    1.1.0 – 1.1.23 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-36062MEDIUM5.9same product

IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 could be vulnerable to information exposure due to th...

CVE-2025-36057MEDIUM5.2same product

IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 is vulnerable to authentication bypass by using the L...

CVE-2025-36107MEDIUM5.9same product

IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 could allow malicious actors to obtain sensitive inform...

CVE-2021-39081MEDIUM5.9same product

IBM Cognos Analytics Mobile for Android 1.1.14 uses weaker than expected cryptographic algorithms that could a...

CVE-2021-39079MEDIUM5.4same product

IBM Cognos Analytics Mobile for Android applications prior to version 1.1.14 is vulnerable to cross-site scrip...