---
id: CVE-2025-36421
title: >-
  IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1
  transmits data in clear text that could allow an attacker to obtain sensitive
  information using man in the middle techniques.
summary: >-
  IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1
  transmits data in clear text that could allow an attacker to obtain sensitive
  information using man in the middle techniques.
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-319
vendor: IBM
product: Controller
affected:
  - Controller >= 11.0.0 <= 11.0.1 FP7
  - Controller >= 11.1.0 <= 11.1.3 FP1
published: '2026-09-18'
updated: '2026-09-19'
sourceUpdated: '2026-09-19T15:16:56.660'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-36421'
references:
  - url: 'https://www.ibm.com/support/pages/node/7287970'
    label: psirt@us.ibm.com
tags:
  - nvd
  - cve.org
epss: 0.00158
epssPercentile: 0.04175
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-19T13:45:03.739556Z'
ingestedAt: '2026-09-18T16:45:41.377Z'
---

## Overview

IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
