Ibm Cognos Analytics vulnerabilities
105 known vulnerabilities affecting ibm/cognos_analytics.
Total CVEs
105
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH24MEDIUM73LOW2
Vulnerabilities
Page 3 of 6
CVE-2021-29716P4MEDIUMCVSS 6.5≥ 11.1.0, < 11.1.7v11.1.7+1 more2021-12-03
CVE-2021-29716 [MEDIUM] CVE-2021-29716: IBM Cognos Analytics 11.1.7 and 11.2.0 could allow a low level user to reas of the application that
IBM Cognos Analytics 11.1.7 and 11.2.0 could allow a low level user to reas of the application that privileged user should only be allowed to view. IBM X-Force ID: 201087.
nvd
CVE-2024-25053P4MEDIUMCVSS 5.9v11.2.0v11.2.1+7 more2024-06-28
CVE-2024-25053 [MEDIUM] CWE-295 CVE-2024-25053: IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, and 12.0.2 is vulnerabl
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, and 12.0.2 is vulnerable to improper certificate validation when using the IBM Planning Analytics Data Source Connection. This could allow an attacker to spoof a trusted entity by interfering in the communication path between IBM Planning Analytics server and IBM Cognos Ana
nvd
CVE-2023-35011P4MEDIUMCVSS 5.4≥ 11.1.0, < 11.1.7≥ 11.2.0, < 11.2.4+3 more2023-08-16
CVE-2023-35011 [MEDIUM] CWE-918 CVE-2023-35011: IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to server-side request forgery (SSRF).
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 257705.
nvd
CVE-2026-15995P4MEDIUMCVSS 5.4≥ 12.1.3 GA Version with build number, ≤ 12.1.3-26062517362026-07-17
CVE-2026-15995 [MEDIUM] CWE-362 CVE-2026-15995: IBM Cognos Analytics 12.1.3 GA Version with build number through 12.1.3-2606251736 could allow an at
IBM Cognos Analytics 12.1.3 GA Version with build number through 12.1.3-2606251736 could allow an attacker to obtain incorrect report summary results or cause report-processing failures due to a race condition in the Agentic AI assistant's concurrent request-handling logic when multiple authenticated users submit report-related tasks simultaneously.
nvd
CVE-2021-29823P4MEDIUMCVSS 6.5≥ 11.1.0, < 11.1.7≥ 11.2.0, < 11.2.3+3 more2022-09-01
CVE-2021-29823 [MEDIUM] CWE-352 CVE-2021-29823: IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which co
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 204465.
nvd
CVE-2020-4301P4MEDIUMCVSS 6.5≥ 11.1.0, < 11.1.7≥ 11.2.0, < 11.2.3+3 more2022-09-01
CVE-2020-4301 [MEDIUM] CWE-352 CVE-2020-4301: IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which co
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 176609.
nvd
CVE-2021-20468P4MEDIUMCVSS 6.5≥ 11.1.0, < 11.1.7≥ 11.2.0, < 11.2.3+3 more2022-09-01
CVE-2021-20468 [MEDIUM] CWE-352 CVE-2021-20468: IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which co
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 196825.
nvd
CVE-2023-38009P4MEDIUMCVSS 5.9v1.12025-01-26
CVE-2023-38009 [MEDIUM] CWE-295 CVE-2023-38009: IBM Cognos Mobile Client 1.1 iOS may be vulnerable to information disclosure through man in the midd
IBM Cognos Mobile Client 1.1 iOS may be vulnerable to information disclosure through man in the middle techniques due to the lack of certificate pinning.
nvd
CVE-2025-0923P4MEDIUMCVSS 5.3≥ 11.2.0, ≤ 11.2.4≥ 12.0.0, ≤ 12.0.4+10 more2025-06-11
CVE-2025-0923 [MEDIUM] CWE-540 CVE-2025-0923: IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 stores source code on the web server that could aid in further attacks against the system.
nvd
CVE-2023-38359P4MEDIUMCVSS 6.1≥ 11.1.1, < 11.1.7≥ 11.2.0, < 11.2.4+5 more2024-02-26
CVE-2023-38359 [MEDIUM] CWE-79 CVE-2023-38359: IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 is vulnerable to cross-site scripting. This vulnerab
IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 260744.
nvd
CVE-2024-41752P4MEDIUMCVSS 6.1≥ 11.2.0, ≤ 11.2.4≥ 12.0.0, ≤ 12.0.32024-12-18
CVE-2024-41752 [MEDIUM] CWE-80 CVE-2024-41752: IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 is vulnerable to HTML injection
IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
nvd
CVE-2021-29867P4MEDIUMCVSS 5.4≥ 11.1.0, < 11.1.7v11.1.7+1 more2021-12-03
CVE-2021-29867 [MEDIUM] CVE-2021-29867: IBM Cognos Analytics 11.1.7 and 11.2.0 could allow an authenticated to view or edit a Jupyter notebo
IBM Cognos Analytics 11.1.7 and 11.2.0 could allow an authenticated to view or edit a Jupyter notebook that they should not have access to. IBM X-Force ID: 206212.
nvd
CVE-2023-28530P4MEDIUMCVSS 5.4≥ 11.1.0, < 11.1.7≥ 11.2.0, < 11.2.4+3 more2023-07-22
CVE-2023-28530 [MEDIUM] CWE-79 CVE-2023-28530: IBM Cognos Analytics 11.1 and 11.2 is vulnerable to stored cross-site scripting, caused by improper
IBM Cognos Analytics 11.1 and 11.2 is vulnerable to stored cross-site scripting, caused by improper validation of SVG Files in Custom Visualizations. A remote attacker could exploit this vulnerability to execute scripts in a victim's Web browser within the security context of the hosting Web site. An attacker could use this vulnerability to steal the
nvd
CVE-2017-1428P4MEDIUMCVSS 6.1v11.0.0v11.0.1+6 more2017-08-29
CVE-2017-1428 [MEDIUM] CWE-20 CVE-2017-1428: IBM Cognos Analytics 11.0 could allow a remote attacker to hijack the clicking action of the victim.
IBM Cognos Analytics 11.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 127583.
nvd
CVE-2021-20493P4MEDIUMCVSS 6.1≥ 11.1.0, < 11.1.7v11.1.7+1 more2021-12-03
CVE-2021-20493 [MEDIUM] CWE-79 CVE-2021-20493: IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site scripting. This vulnerability all
IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 197794.
nvd
CVE-2021-39047P4MEDIUMCVSS 6.1≥ 11.1.0, < 11.1.7v11.1.7+2 more2022-06-24
CVE-2021-39047 [MEDIUM] CWE-79 CVE-2021-39047: IBM Planning Analytics 2.0 and IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 are vulnerable to cro
IBM Planning Analytics 2.0 and IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 214349.
nvd
CVE-2021-39036P4MEDIUMCVSS 6.1v11.1v11.2+1 more2023-05-12
CVE-2021-39036 [MEDIUM] CWE-79 CVE-2021-39036: IBM Cognos Analytics 11.1 and 11.2 is vulnerable to cross-site scripting. This vulnerability allows
IBM Cognos Analytics 11.1 and 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 213966.
nvd
CVE-2016-9711P4MEDIUMCVSS 5.3v11.0.0v11.02018-03-22
CVE-2016-9711 [MEDIUM] CWE-200 CVE-2016-9711: IBM Predictive Solutions Foundation (IBM Cognos Analytics 11.0) reveals sensitive information in det
IBM Predictive Solutions Foundation (IBM Cognos Analytics 11.0) reveals sensitive information in detailed error messages that could aid an attacker in further attacks against the system. IBM X-Force ID: 119619.
nvd
CVE-2021-29719P4MEDIUMCVSS 5.3≥ 11.1.0, < 11.1.7v11.1.7+1 more2021-12-03
CVE-2021-29719 [MEDIUM] CVE-2021-29719: IBM Cognos Analytics 11.1.7 and 11.2.0 could be vulnerable to client side vulnerabilties due to a we
IBM Cognos Analytics 11.1.7 and 11.2.0 could be vulnerable to client side vulnerabilties due to a web response specifying an incorrect content type. IBM X-Force ID: 201091
nvd
CVE-2021-38903P4MEDIUMCVSS 5.4v11.1.7v11.2.0+1 more2022-04-22
CVE-2021-38903 [MEDIUM] CWE-79 CVE-2021-38903: IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting, caused by imp
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim's Web browser within the security context of the hosting Web site, once the URL i
nvd