cbcvebase.

Ibm Cognos Analytics vulnerabilities

105 known vulnerabilities affecting ibm/cognos_analytics.

Total CVEs
105
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH24MEDIUM73LOW2

Vulnerabilities

Page 1 of 6
CVE-2020-4561P2CRITICALCVSS 10.0v11.0.0v11.1.0+2 more2021-06-01
CVE-2020-4561 [CRITICAL] CWE-829 CVE-2020-4561: IBM Cognos Analytics 11.0 and 11.1 DQM API allows submitting of all control requests in unauthentica IBM Cognos Analytics 11.0 and 11.1 DQM API allows submitting of all control requests in unauthenticated sessions. This allows a remote attacker who can access a valid CA endpoint to read and write files to the Cognos Analytics system. IBM X-Force ID: 183903.
nvd
CVE-2019-4178P3CRITICALCVSS 9.1≥ 11.0.0.0, ≤ 11.0.13.0v112019-04-15
CVE-2019-4178 [CRITICAL] CWE-22 CVE-2019-4178: IBM Cognos Analytics 11 could allow a remote attacker to traverse directories on the system. An atta IBM Cognos Analytics 11 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request to write or view arbitrary files on the system. IBM X-Force ID: 158919.
nvd
CVE-2024-51466P3CRITICALCVSS 9.0≥ 11.2.0, < 11.2.4≥ 12.0.0, < 12.0.4+4 more2024-12-20
CVE-2024-51466 [CRITICAL] CWE-917 CVE-2024-51466: IBM Cognos Analytics 11.2.0 through 11.2.4 FP4 and 12.0.0 through 12.0.4 is vulnerable to an Expr IBM Cognos Analytics 11.2.0 through 11.2.4 FP4 and 12.0.0 through 12.0.4 is vulnerable to an Expression Language (EL) Injection vulnerability. A remote attacker could exploit this vulnerability to expose sensitive information, consume memory resources, and/or cause the server to crash when using a specially crafted EL statement.
nvd
CVE-2021-38945P3CRITICALCVSS 9.8≥ 11.1.0, < 11.1.7v11.1.7+2 more2022-06-24
CVE-2021-38945 [CRITICAL] CWE-434 CVE-2021-38945: IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 could allow a remote attacker to upload arbitrary fi IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 could allow a remote attacker to upload arbitrary files, caused by improper content validation. IBM X-Force ID: 211238.
nvd
CVE-2018-1721P3HIGHCVSS 8.8v11.0.0v11.1.0+2 more2019-11-09
CVE-2018-1721 [HIGH] CWE-91 CVE-2018-1721: IBM Cognos Analytics 11.0 and 11.1 is vulnerable to a XML External Entity Injection (XXE) attack whe IBM Cognos Analytics 11.0 and 11.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or cause the web server to make HTTP requests to arbitrary domains. IBM X-Force ID: 147369.
nvd
CVE-2021-29679P3HIGHCVSS 8.8v11.1.7v11.2.02021-10-15
CVE-2021-29679 [HIGH] CWE-94 CVE-2021-29679: IBM Cognos Analytics 11.1.7 and 11.2.0 could allow an authenticated user to execute code remotely du IBM Cognos Analytics 11.1.7 and 11.2.0 could allow an authenticated user to execute code remotely due to incorrectly neutralizaing user-contrlled input that could be interpreted a a server-side include (SSI) directive. IBM X-Force ID: 199915.
nvd
CVE-2022-38708P3CRITICALCVSS 9.1≥ 11.1.0, ≤ 11.1.7≥ 11.2.0, ≤ 11.2.3+2 more2022-12-19
CVE-2022-38708 [CRITICAL] CWE-918 CVE-2022-38708: IBM Cognos Analytics 11.1.7 11.2.0, and 11.2.1 could be vulnerable to a Server-Side Request Forgery IBM Cognos Analytics 11.1.7 11.2.0, and 11.2.1 could be vulnerable to a Server-Side Request Forgery Attack (SSRF) attack by constructing URLs from user-controlled data. This could enable attackers to make arbitrary requests to the internal network or to the local file system. IBM X-Force ID: 234180.
nvd
CVE-2020-4377P3CRITICALCVSS 9.1v11.0.0v11.1.0+2 more2020-08-03
CVE-2020-4377 [CRITICAL] CWE-611 CVE-2020-4377: IBM Cognos Anaytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack whe IBM Cognos Anaytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 179156.
nvd
CVE-2020-4300P3HIGHCVSS 8.2v11.0.0v11.1.0+2 more2021-06-01
CVE-2020-4300 [HIGH] CWE-611 CVE-2020-4300: IBM Cognos Analytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack wh IBM Cognos Analytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 176607.
nvd
CVE-2020-4520P3HIGHCVSS 8.8v11.0.0v11.1.0+2 more2021-06-01
CVE-2020-4520 [HIGH] CWE-79 CVE-2020-4520: IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to inject malicious HTML code that IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to inject malicious HTML code that when viewed by the authenticated victim would execute the code. IBM X-Force ID: 182395.
nvd
CVE-2022-36773P3HIGHCVSS 8.1≥ 11.1.0, < 11.1.7≥ 11.2.0, < 11.2.3+3 more2022-09-01
CVE-2022-36773 [HIGH] CWE-611 CVE-2022-36773: IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to an XML External Entity Injection (X IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 233571.
nvd
CVE-2021-29745P3HIGHCVSS 8.8v11.1.7v11.2.02021-10-15
CVE-2021-29745 [HIGH] CVE-2021-29745: IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to priviledge escalation where a lower evel use IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to priviledge escalation where a lower evel user could have access to the 'New Job' page to which they should not have access to. IBM X-Force ID: 201695.
nvd
CVE-2024-25047P3HIGHCVSS 8.6≥ 11.2.0, < 11.2.4≥ 12.0.0, < 12.0.3+2 more2024-05-02
CVE-2024-25047 [HIGH] CWE-117 CVE-2024-25047: IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.2 is vulnerable to injection atta IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.2 is vulnerable to injection attacks in application logging by not sanitizing user provided data. This could lead to further attacks against the system. IBM X-Force ID: 282956.
nvd
CVE-2019-4723P3HIGHCVSS 7.5v11.0.0v11.1.0+2 more2021-06-01
CVE-2019-4723 [HIGH] CWE-522 CVE-2019-4723: IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain credentials from a user's IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain credentials from a user's browser via incorrect autocomplete settings in New Data Server Connection page. IBM X-Force ID: 172129.
nvd
CVE-2024-40695P3HIGHCVSS 8.0≥ 11.2.0, < 11.2.4≥ 12.0.0, < 12.0.4+4 more2024-12-20
CVE-2024-40695 [HIGH] CWE-434 CVE-2024-40695: IBM Cognos Analytics 11.2.0 through 11.2.4 FP4 and 12.0.0 through 12.0.4 could be vulnerable to IBM Cognos Analytics 11.2.0 through 11.2.4 FP4 and 12.0.0 through 12.0.4 could be vulnerable to malicious file upload by not validating the content of the file uploaded to the web interface. Attackers can make use of this weakness and upload malicious executable files into the system, and it can be sent to victim for performing further attacks.
nvd
CVE-2020-4302P3HIGHCVSS 7.8≥ 11.0.0, < 11.0.13≥ 11.1.0, ≤ 11.1.7+3 more2020-10-12
CVE-2020-4302 [HIGH] CWE-1236 CVE-2020-4302: IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to execute arbitrary code on the sy IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to execute arbitrary code on the system, caused by a CSV injection. By persuading a victim to open a specially-crafted excel file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 176610.
nvd
CVE-2019-4724P3HIGHCVSS 7.5v11.0.0v11.1.0+2 more2021-06-01
CVE-2019-4724 [HIGH] CWE-522 CVE-2019-4724: IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain credentials from a user's IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain credentials from a user's browser via incorrect autocomplete settings in New Content Backup page. IBM X-Force ID: 172130.
nvd
CVE-2019-4730P3HIGHCVSS 7.1v11.0.0v11.1.0+2 more2021-06-01
CVE-2019-4730 [HIGH] CWE-611 CVE-2019-4730: IBM Cognos Analytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack wh IBM Cognos Analytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 172533.
nvd
CVE-2022-43883P3HIGHCVSS 7.5≥ 11.1.0, ≤ 11.1.7≥ 11.2.0, ≤ 11.2.3+2 more2022-12-19
CVE-2022-43883 [HIGH] CWE-116 CVE-2022-43883: IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could be vulnerable to a Log Injection attack by co IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could be vulnerable to a Log Injection attack by constructing URLs from user-controlled data. This could enable attackers to make arbitrary requests to the internal network or to the local file system. IBM X-Force ID: 240266.
nvd
CVE-2021-20470P3HIGHCVSS 7.5≥ 11.1.0, < 11.1.7v11.1.7+1 more2021-12-03
CVE-2021-20470 [HIGH] CWE-521 CVE-2021-20470: IBM Cognos Analytics 11.1.7 and 11.2.0 does not require that users should have strong passwords by d IBM Cognos Analytics 11.1.7 and 11.2.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 196339.
nvd
Ibm Cognos Analytics vulnerabilities | cvebase