---
id: CVE-2025-36076
title: >-
  IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2
  stores sensitive information in source code could be used by an authenticated
  user in further attacks against the system.
summary: >-
  IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2
  stores sensitive information in source code could be used by an authenticated
  user in further attacks against the system.
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-540
vendor: IBM
product: Cognos Analytics
affected:
  - cognos_analytics >= 12.1.0 <= 12.1.3 FP1
  - cognos_analytics >= 12.0.4 <= 12.0.4 FP2
published: '2026-09-18'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T18:17:47.257'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-36076'
references:
  - url: 'https://www.ibm.com/support/pages/node/7287209'
    label: psirt@us.ibm.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-18T16:44:54.712593Z'
ingestedAt: '2026-09-18T16:45:41.376Z'
epss: 0.00295
epssPercentile: 0.22332
---

## Overview

IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 stores sensitive information in source code could be used by an authenticated user in further attacks against the system.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
