Ibm Cognos Analytics vulnerabilities

102 known vulnerabilities affecting ibm/cognos_analytics.

Total CVEs
102
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH22MEDIUM72LOW2

Vulnerabilities

Page 3 of 6
CVE-2021-39047MEDIUMCVSS 6.1≥ 11.1.0, < 11.1.7v11.1.7+2 more2022-06-24
CVE-2021-39047 [MEDIUM] CWE-79 CVE-2021-39047: IBM Planning Analytics 2.0 and IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 are vulnerable to cro IBM Planning Analytics 2.0 and IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 214349.
cvelistv5nvd
CVE-2021-29768MEDIUMCVSS 6.5≥ 11.1.0, < 11.1.7v11.1.7+2 more2022-06-24
CVE-2021-29768 [MEDIUM] CVE-2021-29768: IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a low level user to obtain sensitive inf IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a low level user to obtain sensitive information from the details of the 'Cloud Storage' page for which they should not have access. IBM X-Force ID: 202682.
cvelistv5nvd
CVE-2021-38886HIGHCVSS 8.8v11.1.7v11.2.0+1 more2022-04-22
CVE-2021-38886 [HIGH] CWE-352 CVE-2021-38886: IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site request forgery which co IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 209399.
cvelistv5nvd
CVE-2021-38904MEDIUMCVSS 6.5v11.1.7v11.2.0+1 more2022-04-22
CVE-2021-38904 [MEDIUM] CVE-2021-38904: IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 could allow a remote attacker to obtain credentials IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 could allow a remote attacker to obtain credentials from a user's browser via incorrect autocomplete settings. IBM X-Force ID: 209693.
cvelistv5nvd
CVE-2021-38905MEDIUMCVSS 4.3v11.1.7v11.2.0+1 more2022-04-22
CVE-2021-38905 [MEDIUM] CVE-2021-38905: IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 could allow an authenticated user to view report pag IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 could allow an authenticated user to view report pages that they should not have access to. IBM X-Force ID: 209697.
cvelistv5nvd
CVE-2021-38903MEDIUMCVSS 5.4v11.1.7v11.2.0+1 more2022-04-22
CVE-2021-38903 [MEDIUM] CWE-79 CVE-2021-38903: IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting, caused by imp IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim's Web browser within the security context of the hosting Web site, once the URL i
cvelistv5nvd
CVE-2021-38946MEDIUMCVSS 5.4v11.1.7v11.2.0+1 more2022-04-22
CVE-2021-38946 [MEDIUM] CWE-79 CVE-2021-38946: IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting. This vulnerab IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 211240.
cvelistv5nvd
CVE-2021-29824MEDIUMCVSS 4.3v11.1.7v11.2.0+1 more2022-04-22
CVE-2021-29824 [MEDIUM] CVE-2021-29824: IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to priviledge escalation where a lower IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to priviledge escalation where a lower level user could have read access to to the 'Data Connections' page to which they don't have access. IBM X-Force ID: 204468.
cvelistv5nvd
CVE-2021-20464MEDIUMCVSS 6.5v11.1.7v11.2.0+1 more2022-04-22
CVE-2021-20464 [MEDIUM] CWE-776 CVE-2021-20464: IBM Cognos Analytics PowerPlay (IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7) could be vulnerable IBM Cognos Analytics PowerPlay (IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7) could be vulnerable to an XML Bomb attack by a malicious authenticated user. IBM X-Force ID: 196813.
cvelistv5nvd
CVE-2021-20470HIGHCVSS 7.5≥ 11.1.0, < 11.1.7v11.1.7+1 more2021-12-03
CVE-2021-20470 [HIGH] CWE-521 CVE-2021-20470: IBM Cognos Analytics 11.1.7 and 11.2.0 does not require that users should have strong passwords by d IBM Cognos Analytics 11.1.7 and 11.2.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 196339.
cvelistv5nvd
CVE-2021-29756HIGHCVSS 8.8≥ 11.1.0, < 11.1.7v11.1.7+1 more2021-12-03
CVE-2021-29756 [HIGH] CWE-352 CVE-2021-29756: IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site request forgery (CSRF) in the My IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site request forgery (CSRF) in the My Inbox page which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 202167.
cvelistv5nvd
CVE-2021-29716MEDIUMCVSS 6.5≥ 11.1.0, < 11.1.7v11.1.7+1 more2021-12-03
CVE-2021-29716 [MEDIUM] CVE-2021-29716: IBM Cognos Analytics 11.1.7 and 11.2.0 could allow a low level user to reas of the application that IBM Cognos Analytics 11.1.7 and 11.2.0 could allow a low level user to reas of the application that privileged user should only be allowed to view. IBM X-Force ID: 201087.
cvelistv5nvd
CVE-2021-29867MEDIUMCVSS 5.4≥ 11.1.0, < 11.1.7v11.1.7+1 more2021-12-03
CVE-2021-29867 [MEDIUM] CVE-2021-29867: IBM Cognos Analytics 11.1.7 and 11.2.0 could allow an authenticated to view or edit a Jupyter notebo IBM Cognos Analytics 11.1.7 and 11.2.0 could allow an authenticated to view or edit a Jupyter notebook that they should not have access to. IBM X-Force ID: 206212.
cvelistv5nvd
CVE-2021-20493MEDIUMCVSS 6.1≥ 11.1.0, < 11.1.7v11.1.7+1 more2021-12-03
CVE-2021-20493 [MEDIUM] CWE-79 CVE-2021-20493: IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site scripting. This vulnerability all IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 197794.
cvelistv5nvd
CVE-2021-38909MEDIUMCVSS 5.4≥ 11.1.0, < 11.1.7v11.1.7+1 more2021-12-03
CVE-2021-38909 [MEDIUM] CWE-79 CVE-2021-38909: IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site scripting. This vulnerability all IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 209706.
cvelistv5nvd
CVE-2021-29719MEDIUMCVSS 5.3≥ 11.1.0, < 11.1.7v11.1.7+1 more2021-12-03
CVE-2021-29719 [MEDIUM] CVE-2021-29719: IBM Cognos Analytics 11.1.7 and 11.2.0 could be vulnerable to client side vulnerabilties due to a we IBM Cognos Analytics 11.1.7 and 11.2.0 could be vulnerable to client side vulnerabilties due to a web response specifying an incorrect content type. IBM X-Force ID: 201091
cvelistv5nvd
CVE-2021-29679HIGHCVSS 8.8v11.1.7v11.2.02021-10-15
CVE-2021-29679 [HIGH] CWE-94 CVE-2021-29679: IBM Cognos Analytics 11.1.7 and 11.2.0 could allow an authenticated user to execute code remotely du IBM Cognos Analytics 11.1.7 and 11.2.0 could allow an authenticated user to execute code remotely due to incorrectly neutralizaing user-contrlled input that could be interpreted a a server-side include (SSI) directive. IBM X-Force ID: 199915.
cvelistv5nvd
CVE-2021-29745HIGHCVSS 8.8v11.1.7v11.2.02021-10-15
CVE-2021-29745 [HIGH] CVE-2021-29745: IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to priviledge escalation where a lower evel use IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to priviledge escalation where a lower evel user could have access to the 'New Job' page to which they should not have access to. IBM X-Force ID: 201695.
cvelistv5nvd
CVE-2020-4951LOWCVSS 3.3v11.1.7v11.2.02021-10-15
CVE-2020-4951 [LOW] CWE-200 CVE-2020-4951: IBM Cognos Analytics 11.1.7 and 11.2.0 contains locally cached browser data, that could allow a loca IBM Cognos Analytics 11.1.7 and 11.2.0 contains locally cached browser data, that could allow a local attacker to obtain sensitive information.
cvelistv5nvd
CVE-2021-20461MEDIUMCVSS 6.5≥ 11.0.0, < 11.0.13≥ 11.1.0, < 11.1.7+4 more2021-06-30
CVE-2021-20461 [MEDIUM] CWE-668 CVE-2021-20461: IBM Cognos Analytics 10.0 and 11.1 is susceptible to a weakness in the implementation of the System IBM Cognos Analytics 10.0 and 11.1 is susceptible to a weakness in the implementation of the System Appearance configuration setting. An attacker could potentially bypass business logic to modify the appearance and behavior of the application. IBM X-Force ID: 196770.
cvelistv5nvd