IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 is vulnerable to authentication bypass by using the Local Authentication Framework library which is not needed as biometric authentication is not used in the application.
History

Thu, 07 Aug 2025 00:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:cognos_analytics_mobile:*:*:*:*:*:iphone_os:*:*

Mon, 21 Jul 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 21 Jul 2025 18:30:00 +0000

Type Values Removed Values Added
Description IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 is vulnerable to authentication bypass by using the Local Authentication Framework library which is not needed as biometric authentication is not used in the application.
Title IBM Cognos Analytics Mobile (iOS) authentication bypass
First Time appeared Ibm
Ibm cognos Analytics Mobile
Weaknesses CWE-299
CPEs cpe:2.3:a:ibm:cognos_analytics_mobile:1.1.0:*:*:*:*:ios:*:*
cpe:2.3:a:ibm:cognos_analytics_mobile:1.1.22:*:*:*:*:ios:*:*
Vendors & Products Ibm
Ibm cognos Analytics Mobile
References
Metrics cvssV3_1

{'score': 5.2, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published: 2025-07-21T18:10:32.157Z

Updated: 2025-07-21T18:39:00.437Z

Reserved: 2025-04-15T21:16:11.325Z

Link: CVE-2025-36057

cve-icon Vulnrichment

Updated: 2025-07-21T18:37:41.067Z

cve-icon NVD

Status : Analyzed

Published: 2025-07-21T19:15:28.840

Modified: 2025-08-07T00:43:35.270

Link: CVE-2025-36057

cve-icon Redhat

No data.