4.4
CVE-2025-36187
- EPSS 0.15%
- Veröffentlicht 25.03.2026 21:26:47
- Zuletzt bearbeitet 31.03.2026 20:22:17
- Erkennungen
Multiple Security vulnerabilities affecting IBM Knowledge Catalog Standard Cartridge
IBM Knowledge Catalog Standard Cartridge 5.0.0, 5.0.1, 5.0.2, 5.0.3, 5.1, 5.1.1, 5,1.2, 5.1.3, 5.2.0, 5.2.1 stores potentially sensitive information in log files that could be read by a local privileged user.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Knowledge Catalog Version 5.0.0 SwEdition standard
Ibm ≫ Knowledge Catalog Version 5.0.1 SwEdition standard
Ibm ≫ Knowledge Catalog Version 5.0.2 SwEdition standard
Ibm ≫ Knowledge Catalog Version 5.0.3 SwEdition standard
Ibm ≫ Knowledge Catalog Version 5.1 SwEdition standard
Ibm ≫ Knowledge Catalog Version 5.1.1 SwEdition standard
Ibm ≫ Knowledge Catalog Version 5.1.2 SwEdition standard
Ibm ≫ Knowledge Catalog Version 5.1.3 SwEdition standard
Ibm ≫ Knowledge Catalog Version 5.2.0 SwEdition standard
Ibm ≫ Knowledge Catalog Version 5.2.1 SwEdition standard
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.15% | 0.048 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.4 | 0.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
|
| IBM | 4.4 | 0.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
|
CWE-532 Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.
https://www.ibm.com/support/pages/node/7267542