CVE-2025-36187Disclosure(ibm / knowledge_catalog)

LOWCVSS 4.4 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

IBM Knowledge Catalog Standard Cartridge 5.0.0, 5.0.1, 5.0.2, 5.0.3, 5.1, 5.1.1, 5,1.2, 5.1.3, 5.2.0, 5.2.1 stores potentially sensitive information in log files that could be read by a local privileged user.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-532

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • knowledge_catalog
  • openshift

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
knowledge_catalogopenshift

11 versions affected across 2 products

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-26: 3Technical Details · 2026-03-26: 103-26
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2025-36187 IBM Knowledge Catalog Standard Cartridge 5.0.0, 5.0.1, 5.0.2, 5.0.3, 5.1, 5.1.1, 5,1.2, 5.1.3, 5.2.0, 5.2.1 stores potentially sensitive information in log files that… https://www.cve.org/CVERecord?id=CVE-2025-36187 ----- Traducción: CVE-2025-36187 IBM… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2025‑36187, noting that IBM Knowledge Catalog stores potentially sensitive data in log files, but provides no PoC, exploit, or mitigation details.

    00000168
    61 followersView on X
  • CVE@CVEnew
    General

    CVE-2025-36187 IBM Knowledge Catalog Standard Cartridge 5.0.0, 5.0.1, 5.0.2, 5.0.3, 5.1, 5.1.1, 5,1.2, 5.1.3, 5.2.0, 5.2.1 stores potentially sensitive information in log files that… https://www.cve.org/CVERecord?id=CVE-2025-36187

    Post summary

    CVE-2025-36187 is a vulnerability in IBM Knowledge Catalog Standard Cartridge that may cause sensitive data to be logged. No exploit, patch, or advanced technical details are present in the statement.

    00000194
    56.8K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2025-36187 - Multiple Security vulnerabilities affecting IBM Knowledge Catalog Standard Cartridge Intel Report: https://ift.tt/2wMhf5H

    Post summary

    An alert announces CVE-2025-36187 affecting IBM Knowledge Catalog Standard Cartridge, with an Intel report link provided but no PoC, exploit, or patch information.

    00000145
    286 followersView on X
CPE platform detail11 entries

11 of 11 entries

PartVendorProductVersionTarget SWTarget HW
Appibmknowledge_catalog5.0.0--
Appibmknowledge_catalog5.0.1--
Appibmknowledge_catalog5.0.2--
Appibmknowledge_catalog5.0.3--
Appibmknowledge_catalog5.1--
Appibmknowledge_catalog5.1.1--
Appibmknowledge_catalog5.1.2--
Appibmknowledge_catalog5.1.3--
Appibmknowledge_catalog5.2.0--
Appibmknowledge_catalog5.2.1--
OSredhatopenshift---

Explore more