Junglewise Threat Intelligence

CVE-2025-36421: IBM Controller cleartext transmission of sensitive data

CVE-2025-36421 · Severity: medium · CVSS 5.9 · Published 2026-09-18

Vendors: IBM.

Executive brief

IBM Controller is a business application used to manage financial planning and reporting. A vulnerability allows attackers to intercept and read sensitive data transmitted over the network in cleartext by using man-in-the-middle techniques, potentially exposing confidential business information and credentials.

Technical details

IBM Controller transmits sensitive data in cleartext rather than using encryption, violating CWE-319 (Cleartext Transmission of Sensitive Information). The vulnerability affects versions 11.0.0 through 11.0.1 FP7 and 11.1.0 through 11.1.3 FP1. An unauthenticated attacker with network access can intercept unencrypted communication to obtain sensitive information. The fix requires upgrading to IBM Controller 11.2.0 or applying appropriate security updates from IBM Support.

Affected products

  • IBM Controller 11.0.0 through 11.0.1 FP7, 11.1.0 through 11.1.3 FP1

Timeline

  • 2025-09-18: disclosed

References