4.4
CVE-2025-36187
- EPSS 0.02%
- Veröffentlicht 25.03.2026 21:26:47
- Zuletzt bearbeitet 31.03.2026 20:22:17
- Quelle psirt@us.ibm.com
- CVE-Watchlists
- Unerledigt
Multiple Security vulnerabilities affecting IBM Knowledge Catalog Standard Cartridge
IBM Knowledge Catalog Standard Cartridge 5.0.0, 5.0.1, 5.0.2, 5.0.3, 5.1, 5.1.1, 5,1.2, 5.1.3, 5.2.0, 5.2.1 stores potentially sensitive information in log files that could be read by a local privileged user.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Knowledge Catalog Version5.0.0 SwEditionstandard
Ibm ≫ Knowledge Catalog Version5.0.1 SwEditionstandard
Ibm ≫ Knowledge Catalog Version5.0.2 SwEditionstandard
Ibm ≫ Knowledge Catalog Version5.0.3 SwEditionstandard
Ibm ≫ Knowledge Catalog Version5.1 SwEditionstandard
Ibm ≫ Knowledge Catalog Version5.1.1 SwEditionstandard
Ibm ≫ Knowledge Catalog Version5.1.2 SwEditionstandard
Ibm ≫ Knowledge Catalog Version5.1.3 SwEditionstandard
Ibm ≫ Knowledge Catalog Version5.2.0 SwEditionstandard
Ibm ≫ Knowledge Catalog Version5.2.1 SwEditionstandard
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.02% | 0.03 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.4 | 0.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
|
| psirt@us.ibm.com | 4.4 | 0.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
|
CWE-532 Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.