Rewterz
Multiple Microsoft Windows Products Vulnerabilities
July 22, 2025
Rewterz
North Korean APT Kimsuky aka Black Banshee – Active IOCs
July 22, 2025

Multiple IBM Cognos Analytics Vulnerabilities

Severity

Medium

Analysis Summary

CVE-2025-36057 CVSS:5.2

IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 is vulnerable to authentication bypass by using the Local Authentication Framework library which is not needed as biometric authentication is not used in the application.

CVE-2025-36062 CVSS:5.9

IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 could be vulnerable to information exposure due to the use of unencrypted network traffic.

CVE-2025-36106 CVSS:6.5

IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 could allow malicious actors to view and modify information coming to and from the application which could then be used to access confidential information on the device or network by using a the deprecated or misconfigured AFNetworking library at runtime.

CVE-2025-36107 CVSS:5.9

IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 could allow malicious actors to obtain sensitive information due to the cleartext transmission of data.

Impact

  • Gain Access
  • Information Disclosure

Indicators of Compromise

CVE

  • CVE-2025-36057

  • CVE-2025-36062

  • CVE-2025-36106

  • CVE-2025-36107

Affected Vendors

  • IBM

Affected Products

  • IBM Cognos Analytics Mobile 1.1.0
  • IBM Cognos Analytics Mobile 1.1.22

Remediation

Refer to IBM Website for patch, upgrade, or suggested workaround information.

CVE-2025-36057

CVE-2025-36062

CVE-2025-36106

CVE-2025-36107