CVE-2025-36057
MEDIUMDescription
IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 is vulnerable to authentication bypass by using the Local Authentication Framework library which is not needed as biometric authentication is not used in the application.
Is your site exposed to CVE-2025-36057?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| ibm | cognos_analytics_mobile |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2025-36057? +
How severe is CVE-2025-36057? +
What products are affected by CVE-2025-36057? +
How do I check if I'm vulnerable to CVE-2025-36057? +
Related Vulnerabilities
Incorrect validation of OCSP certificates vulnerability in TheGreenBow VPN, versions 7.5 and 7.6. During the IKEv2 authentication step, the OCSP-enabled …
A security issue exists within CompactLogix® 5380, ControlLogix® 5580, and EN4 communication modules related to CIP Security certificate revocation handling. …
A MongoDB server under specific conditions running on Linux with TLS and CRL revocation status checking enabled, fails to check …
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator flags an out-of-date OCSP …
Check for certificate revocation only considers the first matching CRL and ignores other valid CRLs of the same CA in …
notion-go is a collection of libraries for supporting sign and verify OCI artifacts. Based on Notary Project specifications. This issue …