cbcvebase.
CVE-2025-0823
published 2025-02-28

CVE-2025-0823: IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 and 12.0.0 through 12.0.4 could allow a remote attacker to traverse directories on the system. An attacker could…

PriorityP341medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.55%
42.3th percentile
IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 and 12.0.0 through 12.0.4 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.

Affected

6 ranges
VendorProductVersion rangeFixed in
ibmcognos_analytics
ibmcognos_analytics
ibmcognos_analytics>= 11.2.0 < 11.2.411.2.4
ibmcognos_analytics11.2.0 – 11.2.4 FP5
ibmcognos_analytics>= 12.0.0 < 12.0.412.0.4
ibmcognos_analytics12.0.0 – 12.0.4
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.