Ibm Cognos Analytics vulnerabilities
105 known vulnerabilities affecting ibm/cognos_analytics.
Total CVEs
105
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH24MEDIUM73LOW2
Vulnerabilities
Page 2 of 6
CVE-2024-49352P3HIGHCVSS 7.1≥ 11.2.0, < 11.2.4≥ 12.0.0, < 12.0.4+3 more2025-02-05
CVE-2024-49352 [HIGH] CWE-611 CVE-2024-49352: IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
nvd
CVE-2025-0823P3MEDIUMCVSS 6.5≥ 11.2.0, < 11.2.4≥ 12.0.0, < 12.0.4+4 more2025-02-28
CVE-2025-0823 [MEDIUM] CWE-22 CVE-2025-0823: IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 and 12.0.0 through 12.0.4 could allow a remote attack
IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 and 12.0.0 through 12.0.4 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
nvd
CVE-2021-38886P3HIGHCVSS 8.8v11.1.7v11.2.0+1 more2022-04-22
CVE-2021-38886 [HIGH] CWE-352 CVE-2021-38886: IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site request forgery which co
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 209399.
nvd
CVE-2019-4183P3HIGHCVSS 7.5v11.0.0v11.1.0+2 more2019-09-17
CVE-2019-4183 [HIGH] CWE-400 CVE-2019-4183: IBM Cognos Analytics 11.0, and 11.1 is vulnerable to a denial of service attack that could allow a r
IBM Cognos Analytics 11.0, and 11.1 is vulnerable to a denial of service attack that could allow a remote user to send specially crafted requests that would consume all available CPU and memory resources. IBM X-Force ID: 158973.
nvd
CVE-2022-30614P3HIGHCVSS 7.5≥ 11.1.0, < 11.1.7≥ 11.2.0, < 11.2.3+3 more2022-09-01
CVE-2022-30614 [HIGH] CVE-2022-30614: IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to a denial of service via email flood
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to a denial of service via email flooding caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume all available CPU resources. IBM X-Force ID: 227591.
nvd
CVE-2025-36126P3HIGHCVSS 7.6≥ 12.1.0, < 12.1.2v11.2+29 more2026-05-26
CVE-2025-36126 [HIGH] CWE-79 CVE-2025-36126: IBM Cognos Analytics 11.2.0, 12.0, and 12.1.0 and IBM Cognos Transformer 12.0, 11.2.4, and 12.1.0 is
IBM Cognos Analytics 11.2.0, 12.0, and 12.1.0 and IBM Cognos Transformer 12.0, 11.2.4, and 12.1.0 is vulnerable to stored cross-site scripting (XSS) in Cognos Adminstration. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure
nvd
CVE-2021-29756P3HIGHCVSS 8.8≥ 11.1.0, < 11.1.7v11.1.7+1 more2021-12-03
CVE-2021-29756 [HIGH] CWE-352 CVE-2021-29756: IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site request forgery (CSRF) in the My
IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site request forgery (CSRF) in the My Inbox page which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 202167.
nvd
CVE-2025-3633P3HIGHCVSS 8.2≥ 11.2.0, < 11.2.4≥ 12.0.0, < 12.0.4+6 more2026-05-27
CVE-2025-3633 [HIGH] CWE-79 CVE-2025-3633: IBM Cognos Analytics 11.2.0, 11.2.4, 12.0, and 12.1.0 and IBM Cognos Transformer 11.2.4, 12.0, and 1
IBM Cognos Analytics 11.2.0, 11.2.4, 12.0, and 12.1.0 and IBM Cognos Transformer 11.2.4, 12.0, and 12.1.0 are vulnerable to cross-site scripting (XSS). This vulnerability allows a remote attacker to inject arbitrary JavaScript code into the web user interface, which may alter the intended functionality and could lead to the disclosure of credentials with
nvd
CVE-2025-25032P3HIGHCVSS 7.5≥ 11.2.0, ≤ 11.2.4≥ 12.0.0, ≤ 12.0.4+10 more2025-06-11
CVE-2025-25032 [HIGH] CWE-770 CVE-2025-25032: IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 could allow an authenticated user to cause a denial of service by sending a specially crafted request that would exhaust memory resources.
nvd
CVE-2024-56340P3MEDIUMCVSS 6.5≥ 11.2.0, < 11.2.4≥ 12.0.0, < 12.0.4+3 more2025-02-28
CVE-2024-56340 [MEDIUM] CWE-23 CVE-2024-56340: IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 is vulnerable to local file inclusion vulnerability,
IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 is vulnerable to local file inclusion vulnerability, allowing an attacker to access sensitive files by inserting path traversal payloads inside the deficon parameter.
nvd
CVE-2020-4388P3HIGHCVSS 8.2≥ 11.0.0, < 11.0.13≥ 11.1.0, ≤ 11.1.7+3 more2020-10-12
CVE-2020-4388 [HIGH] CWE-755 CVE-2020-4388: IBM Cognos Analytics 11.0 and 11.1 could be vulnerable to a denial of service attack by failing to c
IBM Cognos Analytics 11.0 and 11.1 could be vulnerable to a denial of service attack by failing to catch exceptions in a servlet also exposing debug information could also be used in future attacks. IBM X-Force ID: 179270.
nvd
CVE-2019-4343P3MEDIUMCVSS 6.5v11.0.0v11.1.0+2 more2019-12-30
CVE-2019-4343 [MEDIUM] CWE-863 CVE-2019-4343: IBM Cognos Analytics 11.0 and 11.1 allows overly permissive cross-origin resource sharing which coul
IBM Cognos Analytics 11.0 and 11.1 allows overly permissive cross-origin resource sharing which could allow an attacker to transfer private information. An attacker could exploit this vulnerability to access content that should be restricted. IBM X-Force ID: 161422.
nvd
CVE-2017-1779P3HIGHCVSS 7.8v11.0.0v11.0.1+10 more2018-01-29
CVE-2017-1779 [HIGH] CWE-522 CVE-2017-1779: IBM Cognos Analytics 11.0 could store cached credentials locally that could be obtained by a local u
IBM Cognos Analytics 11.0 could store cached credentials locally that could be obtained by a local user. IBM X-Force ID: 136824.
nvd
CVE-2021-29768P4MEDIUMCVSS 6.5≥ 11.1.0, < 11.1.7v11.1.7+2 more2022-06-24
CVE-2021-29768 [MEDIUM] CVE-2021-29768: IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a low level user to obtain sensitive inf
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a low level user to obtain sensitive information from the details of the 'Cloud Storage' page for which they should not have access. IBM X-Force ID: 202682.
nvd
CVE-2021-38904P4MEDIUMCVSS 6.5v11.1.7v11.2.0+1 more2022-04-22
CVE-2021-38904 [MEDIUM] CVE-2021-38904: IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 could allow a remote attacker to obtain credentials
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 could allow a remote attacker to obtain credentials from a user's browser via incorrect autocomplete settings. IBM X-Force ID: 209693.
nvd
CVE-2022-34357P4MEDIUMCVSS 6.5≥ 11.1.1, < 11.1.7≥ 11.2.0, < 11.2.4+5 more2024-02-26
CVE-2022-34357 [MEDIUM] CWE-770 CVE-2022-34357: IBM Cognos Analytics Mobile Server 11.1.7, 11.2.4, and 12.0.0 is vulnerable to Denial of Service due
IBM Cognos Analytics Mobile Server 11.1.7, 11.2.4, and 12.0.0 is vulnerable to Denial of Service due to due to weak or absence of rate limiting. By making unlimited http requests, it is possible for a single user to exhaust server resources over a period of time making service unavailable for other legitimate users. IBM X-Force ID: 230510.
nvd
CVE-2022-34339P4MEDIUMCVSS 6.5≥ 11.1.0, < 11.1.7v11.1.7+2 more2022-11-03
CVE-2022-34339 [MEDIUM] CWE-312 CVE-2022-34339: "IBM Cognos Analytics 11.2.1, 11.2.0, 11.1.7 stores user credentials in plain clear text which can b
"IBM Cognos Analytics 11.2.1, 11.2.0, 11.1.7 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 229963."
nvd
CVE-2021-20464P4MEDIUMCVSS 6.5v11.1.7v11.2.0+1 more2022-04-22
CVE-2021-20464 [MEDIUM] CWE-776 CVE-2021-20464: IBM Cognos Analytics PowerPlay (IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7) could be vulnerable
IBM Cognos Analytics PowerPlay (IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7) could be vulnerable to an XML Bomb attack by a malicious authenticated user. IBM X-Force ID: 196813.
nvd
CVE-2019-4471P4MEDIUMCVSS 6.5v11.0.0v11.1.0+2 more2021-06-01
CVE-2019-4471 [MEDIUM] CWE-311 CVE-2019-4471: IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain sensitive information, ca
IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain sensitive information, caused by the failure to set the secure flag for a sensitive cookie in an HTTPS session. A remote attacker could exploit this vulnerability to obtain sensitive information. IBM X-Force ID: 163780.
nvd
CVE-2021-20461P4MEDIUMCVSS 6.5≥ 11.0.0, < 11.0.13≥ 11.1.0, < 11.1.7+4 more2021-06-30
CVE-2021-20461 [MEDIUM] CWE-668 CVE-2021-20461: IBM Cognos Analytics 10.0 and 11.1 is susceptible to a weakness in the implementation of the System
IBM Cognos Analytics 10.0 and 11.1 is susceptible to a weakness in the implementation of the System Appearance configuration setting. An attacker could potentially bypass business logic to modify the appearance and behavior of the application. IBM X-Force ID: 196770.
nvd