Ibm Cognos Analytics vulnerabilities
102 known vulnerabilities affecting ibm/cognos_analytics.
Total CVEs
102
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH22MEDIUM72LOW2
Vulnerabilities
Page 3 of 6
CVE-2021-39047MEDIUMCVSS 6.1≥ 11.1.0, < 11.1.7v11.1.7+2 more2022-06-24
CVE-2021-39047 [MEDIUM] CWE-79 CVE-2021-39047: IBM Planning Analytics 2.0 and IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 are vulnerable to cro
IBM Planning Analytics 2.0 and IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 214349.
cvelistv5nvd
CVE-2021-29768MEDIUMCVSS 6.5≥ 11.1.0, < 11.1.7v11.1.7+2 more2022-06-24
CVE-2021-29768 [MEDIUM] CVE-2021-29768: IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a low level user to obtain sensitive inf
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a low level user to obtain sensitive information from the details of the 'Cloud Storage' page for which they should not have access. IBM X-Force ID: 202682.
cvelistv5nvd
CVE-2021-38886HIGHCVSS 8.8v11.1.7v11.2.0+1 more2022-04-22
CVE-2021-38886 [HIGH] CWE-352 CVE-2021-38886: IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site request forgery which co
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 209399.
cvelistv5nvd
CVE-2021-38904MEDIUMCVSS 6.5v11.1.7v11.2.0+1 more2022-04-22
CVE-2021-38904 [MEDIUM] CVE-2021-38904: IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 could allow a remote attacker to obtain credentials
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 could allow a remote attacker to obtain credentials from a user's browser via incorrect autocomplete settings. IBM X-Force ID: 209693.
cvelistv5nvd
CVE-2021-38905MEDIUMCVSS 4.3v11.1.7v11.2.0+1 more2022-04-22
CVE-2021-38905 [MEDIUM] CVE-2021-38905: IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 could allow an authenticated user to view report pag
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 could allow an authenticated user to view report pages that they should not have access to. IBM X-Force ID: 209697.
cvelistv5nvd
CVE-2021-38903MEDIUMCVSS 5.4v11.1.7v11.2.0+1 more2022-04-22
CVE-2021-38903 [MEDIUM] CWE-79 CVE-2021-38903: IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting, caused by imp
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim's Web browser within the security context of the hosting Web site, once the URL i
cvelistv5nvd
CVE-2021-38946MEDIUMCVSS 5.4v11.1.7v11.2.0+1 more2022-04-22
CVE-2021-38946 [MEDIUM] CWE-79 CVE-2021-38946: IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting. This vulnerab
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 211240.
cvelistv5nvd
CVE-2021-29824MEDIUMCVSS 4.3v11.1.7v11.2.0+1 more2022-04-22
CVE-2021-29824 [MEDIUM] CVE-2021-29824: IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to priviledge escalation where a lower
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to priviledge escalation where a lower level user could have read access to to the 'Data Connections' page to which they don't have access. IBM X-Force ID: 204468.
cvelistv5nvd
CVE-2021-20464MEDIUMCVSS 6.5v11.1.7v11.2.0+1 more2022-04-22
CVE-2021-20464 [MEDIUM] CWE-776 CVE-2021-20464: IBM Cognos Analytics PowerPlay (IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7) could be vulnerable
IBM Cognos Analytics PowerPlay (IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7) could be vulnerable to an XML Bomb attack by a malicious authenticated user. IBM X-Force ID: 196813.
cvelistv5nvd
CVE-2021-20470HIGHCVSS 7.5≥ 11.1.0, < 11.1.7v11.1.7+1 more2021-12-03
CVE-2021-20470 [HIGH] CWE-521 CVE-2021-20470: IBM Cognos Analytics 11.1.7 and 11.2.0 does not require that users should have strong passwords by d
IBM Cognos Analytics 11.1.7 and 11.2.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 196339.
cvelistv5nvd
CVE-2021-29756HIGHCVSS 8.8≥ 11.1.0, < 11.1.7v11.1.7+1 more2021-12-03
CVE-2021-29756 [HIGH] CWE-352 CVE-2021-29756: IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site request forgery (CSRF) in the My
IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site request forgery (CSRF) in the My Inbox page which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 202167.
cvelistv5nvd
CVE-2021-29716MEDIUMCVSS 6.5≥ 11.1.0, < 11.1.7v11.1.7+1 more2021-12-03
CVE-2021-29716 [MEDIUM] CVE-2021-29716: IBM Cognos Analytics 11.1.7 and 11.2.0 could allow a low level user to reas of the application that
IBM Cognos Analytics 11.1.7 and 11.2.0 could allow a low level user to reas of the application that privileged user should only be allowed to view. IBM X-Force ID: 201087.
cvelistv5nvd
CVE-2021-29867MEDIUMCVSS 5.4≥ 11.1.0, < 11.1.7v11.1.7+1 more2021-12-03
CVE-2021-29867 [MEDIUM] CVE-2021-29867: IBM Cognos Analytics 11.1.7 and 11.2.0 could allow an authenticated to view or edit a Jupyter notebo
IBM Cognos Analytics 11.1.7 and 11.2.0 could allow an authenticated to view or edit a Jupyter notebook that they should not have access to. IBM X-Force ID: 206212.
cvelistv5nvd
CVE-2021-20493MEDIUMCVSS 6.1≥ 11.1.0, < 11.1.7v11.1.7+1 more2021-12-03
CVE-2021-20493 [MEDIUM] CWE-79 CVE-2021-20493: IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site scripting. This vulnerability all
IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 197794.
cvelistv5nvd
CVE-2021-38909MEDIUMCVSS 5.4≥ 11.1.0, < 11.1.7v11.1.7+1 more2021-12-03
CVE-2021-38909 [MEDIUM] CWE-79 CVE-2021-38909: IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site scripting. This vulnerability all
IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 209706.
cvelistv5nvd
CVE-2021-29719MEDIUMCVSS 5.3≥ 11.1.0, < 11.1.7v11.1.7+1 more2021-12-03
CVE-2021-29719 [MEDIUM] CVE-2021-29719: IBM Cognos Analytics 11.1.7 and 11.2.0 could be vulnerable to client side vulnerabilties due to a we
IBM Cognos Analytics 11.1.7 and 11.2.0 could be vulnerable to client side vulnerabilties due to a web response specifying an incorrect content type. IBM X-Force ID: 201091
cvelistv5nvd
CVE-2021-29679HIGHCVSS 8.8v11.1.7v11.2.02021-10-15
CVE-2021-29679 [HIGH] CWE-94 CVE-2021-29679: IBM Cognos Analytics 11.1.7 and 11.2.0 could allow an authenticated user to execute code remotely du
IBM Cognos Analytics 11.1.7 and 11.2.0 could allow an authenticated user to execute code remotely due to incorrectly neutralizaing user-contrlled input that could be interpreted a a server-side include (SSI) directive. IBM X-Force ID: 199915.
cvelistv5nvd
CVE-2021-29745HIGHCVSS 8.8v11.1.7v11.2.02021-10-15
CVE-2021-29745 [HIGH] CVE-2021-29745: IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to priviledge escalation where a lower evel use
IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to priviledge escalation where a lower evel user could have access to the 'New Job' page to which they should not have access to. IBM X-Force ID: 201695.
cvelistv5nvd
CVE-2020-4951LOWCVSS 3.3v11.1.7v11.2.02021-10-15
CVE-2020-4951 [LOW] CWE-200 CVE-2020-4951: IBM Cognos Analytics 11.1.7 and 11.2.0 contains locally cached browser data, that could allow a loca
IBM Cognos Analytics 11.1.7 and 11.2.0 contains locally cached browser data, that could allow a local attacker to obtain sensitive information.
cvelistv5nvd
CVE-2021-20461MEDIUMCVSS 6.5≥ 11.0.0, < 11.0.13≥ 11.1.0, < 11.1.7+4 more2021-06-30
CVE-2021-20461 [MEDIUM] CWE-668 CVE-2021-20461: IBM Cognos Analytics 10.0 and 11.1 is susceptible to a weakness in the implementation of the System
IBM Cognos Analytics 10.0 and 11.1 is susceptible to a weakness in the implementation of the System Appearance configuration setting. An attacker could potentially bypass business logic to modify the appearance and behavior of the application. IBM X-Force ID: 196770.
cvelistv5nvd