Multiple Microsoft Windows Products Vulnerabilities
July 22, 2025North Korean APT Kimsuky aka Black Banshee – Active IOCs
July 22, 2025Multiple Microsoft Windows Products Vulnerabilities
July 22, 2025North Korean APT Kimsuky aka Black Banshee – Active IOCs
July 22, 2025Severity
Medium
Analysis Summary
CVE-2025-36057 CVSS:5.2
IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 is vulnerable to authentication bypass by using the Local Authentication Framework library which is not needed as biometric authentication is not used in the application.
CVE-2025-36062 CVSS:5.9
IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 could be vulnerable to information exposure due to the use of unencrypted network traffic.
CVE-2025-36106 CVSS:6.5
IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 could allow malicious actors to view and modify information coming to and from the application which could then be used to access confidential information on the device or network by using a the deprecated or misconfigured AFNetworking library at runtime.
CVE-2025-36107 CVSS:5.9
IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 could allow malicious actors to obtain sensitive information due to the cleartext transmission of data.
Impact
- Gain Access
- Information Disclosure
Indicators of Compromise
CVE
CVE-2025-36057
CVE-2025-36062
CVE-2025-36106
CVE-2025-36107
Affected Vendors
- IBM
Affected Products
- IBM Cognos Analytics Mobile 1.1.0
- IBM Cognos Analytics Mobile 1.1.22
Remediation
Refer to IBM Website for patch, upgrade, or suggested workaround information.