Severity
7.5HIGH
EPSS
0.2%
top 53.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 11

Description

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 could allow an authenticated user to cause a denial of service by sending a specially crafted request that would exhaust memory resources.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

NVDibm/cognos_analytics11.2.011.2.4+2
CVEListV5ibm/cognos_analytics10 versions+9

🔴Vulnerability Details

2
GHSA
GHSA-v9x3-f4g7-pgm4: IBM Cognos Analytics 112025-06-11
CVEList
IBM Cognos Analytics denial of service2025-06-11

📋Vendor Advisories

1
Microsoft
zlib before 1.2.12 allows memory corruption when deflating (i.e. when compressing) if the input has many distant matches.2022-03-08
CVE-2025-25032 (HIGH CVSS 7.5) | IBM Cognos Analytics 11.2.0 | cvebase.io