CVE-2025-0923
MEDIUMDescription
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 stores source code on the web server that could aid in further attacks against the system.
Is your site exposed to CVE-2025-0923?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| ibm | cognos_analytics |
| ibm | cognos_analytics |
| ibm | cognos_analytics |
| ibm | cognos_analytics |
| ibm | cognos_analytics |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2025-0923? +
How severe is CVE-2025-0923? +
What products are affected by CVE-2025-0923? +
How do I check if I'm vulnerable to CVE-2025-0923? +
Related Vulnerabilities
PMD is an extensible multilanguage static code analyzer. The passphrase for the PMD and PMD Designer release signing keys are …
A inclusion of sensitive information in source code vulnerability in Fortinet FortiMonitorOnSight 7.2.4 through 7.2.7, FortiMonitorOnSight 7.2.0 through 7.2.2 may …
An issue in Loggrove v.1.0 allows a remote attacker to obtain sensitive information via the read.py component.
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Inclusion of Sensitive Information in Source Code …
Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is invoked with a single file path …
An exposure of sensitive information vulnerability has been reported to affect QNAP AI Core. If exploited, the vulnerability could allow …