Ibm Cognos Analytics vulnerabilities
105 known vulnerabilities affecting ibm/cognos_analytics.
Total CVEs
105
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH24MEDIUM73LOW2
Vulnerabilities
Page 4 of 6
CVE-2023-43051P4MEDIUMCVSS 5.4≥ 11.1.1, < 11.1.7≥ 11.2.0, < 11.2.4+5 more2024-02-26
CVE-2023-43051 [MEDIUM] CWE-79 CVE-2023-43051: IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 is vulnerable to cross-site scripting. This vulnerab
IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 267451.
nvd
CVE-2023-35009P4MEDIUMCVSS 5.3≥ 11.1.0, < 11.1.7≥ 11.2.0, < 11.2.4+3 more2023-08-16
CVE-2023-35009 [MEDIUM] CWE-209 CVE-2023-35009: IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a remote attacker to obtain system infor
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a remote attacker to obtain system information without authentication which could be used in reconnaissance to gather information that could be used for future attacks. IBM X-Force ID: 257703.
nvd
CVE-2019-4366P4MEDIUMCVSS 5.3v11.0.0v11.1.0+2 more2020-08-03
CVE-2019-4366 [MEDIUM] CVE-2019-4366: IBM Cognos Analytics 11.0 and 11.1 is susceptible to an information disclosure vulnerability where a
IBM Cognos Analytics 11.0 and 11.1 is susceptible to an information disclosure vulnerability where an attacker could gain access to cached browser data. IBM X-Force ID: 161748.
nvd
CVE-2019-4645P4MEDIUMCVSS 6.1v11.0.0v11.1.0+2 more2019-11-09
CVE-2019-4645 [MEDIUM] CWE-79 CVE-2019-4645: IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 170881.
nvd
CVE-2022-39160P4MEDIUMCVSS 6.1≥ 11.1.0, < 11.1.7≥ 11.2.0, ≤ 11.2.3+2 more2022-12-19
CVE-2022-39160 [MEDIUM] CWE-79 CVE-2022-39160: IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting. This vulnera
IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 235064.
nvd
CVE-2019-4139P4MEDIUMCVSS 5.4v11.0.0v11.1.0+2 more2019-05-29
CVE-2019-4139 [MEDIUM] CWE-79 CVE-2019-4139: IBM Cognos Analytics 11.0, 11.1.0, and 11.1.1 is vulnerable to cross-site scripting. This vulnerabil
IBM Cognos Analytics 11.0, 11.1.0, and 11.1.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 158335.
nvd
CVE-2020-4354P4MEDIUMCVSS 5.4v11.0.0v11.1.0+2 more2021-06-01
CVE-2020-4354 [MEDIUM] CWE-79 CVE-2020-4354: IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 178506.
nvd
CVE-2019-4653P4MEDIUMCVSS 5.4v11.0.0v11.1.0+2 more2021-06-01
CVE-2019-4653 [MEDIUM] CWE-79 CVE-2019-4653: IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 170964.
nvd
CVE-2016-0217P4MEDIUMCVSS 5.4v11.0.0v11.0.1+3 more2017-02-01
CVE-2016-0217 [MEDIUM] CWE-79 CVE-2016-0217: IBM Cognos Business Intelligence and IBM Cognos Analytics are vulnerable to stored cross-site script
IBM Cognos Business Intelligence and IBM Cognos Analytics are vulnerable to stored cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim's Web browser within the security context of the hosting Web site
nvd
CVE-2021-38909P4MEDIUMCVSS 5.4≥ 11.1.0, < 11.1.7v11.1.7+1 more2021-12-03
CVE-2021-38909 [MEDIUM] CWE-79 CVE-2021-38909: IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site scripting. This vulnerability all
IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 209706.
nvd
CVE-2021-38946P4MEDIUMCVSS 5.4v11.1.7v11.2.0+1 more2022-04-22
CVE-2021-38946 [MEDIUM] CWE-79 CVE-2021-38946: IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting. This vulnerab
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 211240.
nvd
CVE-2023-25929P4MEDIUMCVSS 5.4≥ 11.1.0, < 11.1.7≥ 11.2.0, < 11.2.4+3 more2023-07-22
CVE-2023-25929 [MEDIUM] CWE-79 CVE-2023-25929: IBM Cognos Analytics 11.1 and 11.2 is vulnerable to cross-site scripting. This vulnerability allows
IBM Cognos Analytics 11.1 and 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 247861.
nvd
CVE-2024-40703P4MEDIUMCVSS 5.5≥ 11.2.0, ≤ 11.2.3≥ 12.0.0, < 12.0.3+3 more2024-09-22
CVE-2024-40703 [MEDIUM] CWE-522 CVE-2024-40703: IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and IBM
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and IBM Cognos Analytics Reports for iOS 11.0.0.7 could allow a local attacker to obtain sensitive information in the form of an API key. An attacker could use this information to launch further attacks against affected applications.
nvd
CVE-2024-25041P4MEDIUMCVSS 5.4≥ 11.2.0, ≤ 11.2.3≥ 12.0.0, ≤ 12.0.2+2 more2024-06-28
CVE-2024-25041 [MEDIUM] CWE-79 CVE-2024-25041: IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, and 12.0.2 is potential
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, and 12.0.2 is potentially vulnerable to cross site scripting (XSS). A remote attacker could execute malicious commands due to improper validation of column headings in Cognos Assistant. IBM X-Force ID: 282780.
nvd
CVE-2022-43887P4MEDIUMCVSS 5.3≥ 11.1.0, < 11.1.7≥ 11.2.0, ≤ 11.2.3+2 more2022-12-19
CVE-2022-43887 [MEDIUM] CWE-532 CVE-2022-43887: IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could be vulnerable to sensitive information exposu
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could be vulnerable to sensitive information exposure by passing API keys to log files. If these keys contain sensitive information, it could lead to further attacks. IBM X-Force ID: 240450.
nvd
CVE-2023-30996P4MEDIUMCVSS 5.3≥ 11.1.1, < 11.1.7≥ 11.2.0, < 11.2.4+5 more2024-02-26
CVE-2023-30996 [MEDIUM] CWE-346 CVE-2023-30996: IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 could be vulnerable to information leakage due to un
IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 could be vulnerable to information leakage due to unverified sources in messages sent between Windows objects of different origins. IBM X-Force ID: 254290.
nvd
CVE-2024-52900P4MEDIUMCVSS 5.4≥ 11.2.0, < 11.2.4≥ 12.0.0, < 12.0.4+4 more2025-06-28
CVE-2024-52900 [MEDIUM] CWE-79 CVE-2024-52900: IBM Cognos Analytics 11.2.0 through 12.2.4 Fix Pack 5 and 12.0.0 through 12.0.4 is vulnerable to sto
IBM Cognos Analytics 11.2.0 through 12.2.4 Fix Pack 5 and 12.0.0 through 12.0.4 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2017-1427P4MEDIUMCVSS 6.1v11.0.0v11.0.1+6 more2017-08-29
CVE-2017-1427 [MEDIUM] CWE-79 CVE-2017-1427: IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to
IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 127579.
nvd
CVE-2024-25042P4MEDIUMCVSS 6.1≥ 11.2.0, ≤ 11.2.4≥ 12.0.0, ≤ 12.0.32024-12-18
CVE-2024-25042 [MEDIUM] CWE-79 CVE-2024-25042: IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 is potentially vulnerable t
IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3
is potentially vulnerable to Cross Site Scripting (XSS). A remote attacker could execute malicious commands due to improper validation of column headings in Cognos Explorations.
nvd
CVE-2019-4342P4MEDIUMCVSS 5.4v11.0.0v11.1.0+2 more2019-09-17
CVE-2019-4342 [MEDIUM] CWE-79 CVE-2019-4342: IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 161421.
nvd