CVE-2025-1994

IBM Cognos Command Center 10.2.4.1 and 10.2.5 



could allow a local user to execute arbitrary code on the system due to the use of unsafe use of the BinaryFormatter function.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
ibmCNA
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 3%
VendorProductVersion
ibmcognos_command_center
10.2.4.1
ibmcognos_command_center
10.2.5
𝑥
= Vulnerable software versions