IBM Cognos Command Center code execution
Published Aug 26, 2025
7.8
HIGHCVSS 3.1
EPSS 0.16%
Description
IBM Cognos Command Center 10.2.4.1 and 10.2.5
could allow a local user to execute arbitrary code on the system due to the use of unsafe use of the BinaryFormatter function.
Affected products
-
Affected
- 10.2.4.1
- 10.2.5
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| IBM | Cognos Command Center | unaffected | Affected
|
- 10.2.4.1
- 10.2.5
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
IBM strongly recommends addressing the vulnerability now by upgrading.
Affected Product(s)VersionFixIBM Cognos Command Center10.2.5 IBM Cognos Command Center 10.2.5 FP1 IF1 available for download from Fix Central https://www.ibm.com/support/pages/node/7239167 IBM Cognos Command Center10.2.4.1 IBM Cognos Command Center 10.2.5 FP1 IF1 available for download from Fix Central https://www.ibm.com/support/pages/node/7239167
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-25811 Advisory
- https://www.ibm.com/support/pages/node/7242159 vendor-advisorypatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-25811 | Advisory | |
| https://www.ibm.com/support/pages/node/7242159 | vendor-advisorypatchVendor Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data