cbcvebase.

Ibm Cognos Analytics vulnerabilities

105 known vulnerabilities affecting ibm/cognos_analytics.

Total CVEs
105
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH24MEDIUM73LOW2

Vulnerabilities

Page 5 of 6
CVE-2019-4555P4MEDIUMCVSS 5.4≥ 11.0.0, ≤ 11.0.12≥ 11.1.0, < 11.1.4+3 more2019-12-20
CVE-2019-4555 [MEDIUM] CWE-79 CVE-2019-4555: IBM Cognos Analytics 11.0 and 11.0 is vulnerable to cross-site scripting. This vulnerability allows IBM Cognos Analytics 11.0 and 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 166204.
nvd
CVE-2019-4623P4MEDIUMCVSS 5.4v11.0.0v11.1.0+2 more2019-12-30
CVE-2019-4623 [MEDIUM] CWE-79 CVE-2019-4623: IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 168924.
nvd
CVE-2018-1413P4MEDIUMCVSS 5.4≥ 11.0.0.0, ≤ 11.0.10.0v11.02018-05-07
CVE-2018-1413 [MEDIUM] CWE-79 CVE-2018-1413: IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138819.
nvd
CVE-2017-1535P4MEDIUMCVSS 5.4v11.0.0v11.0.1+6 more2017-08-29
CVE-2017-1535 [MEDIUM] CWE-79 CVE-2017-1535: IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 130677.
nvd
CVE-2017-1485P4MEDIUMCVSS 5.4v11.0.0v11.0.1+6 more2017-08-29
CVE-2017-1485 [MEDIUM] CWE-79 CVE-2017-1485: IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128623.
nvd
CVE-2016-3031P4MEDIUMCVSS 5.4v11.0.0v11.0.1+3 more2017-04-05
CVE-2016-3031 [MEDIUM] CWE-79 CVE-2016-3031: IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1998887.
nvd
CVE-2016-3015P4MEDIUMCVSS 5.4v11.0.0v11.0.1+3 more2017-04-05
CVE-2016-3015 [MEDIUM] CWE-79 CVE-2016-3015: IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1998887.
nvd
CVE-2016-3032P4MEDIUMCVSS 5.4v11.0.0v11.0.1+5 more2017-05-10
CVE-2016-3032 [MEDIUM] CWE-79 CVE-2016-3032: IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 114516.
nvd
CVE-2021-39009P4MEDIUMCVSS 5.5≥ 11.1.0, < 11.1.7≥ 11.2.0, < 11.2.3+3 more2022-09-01
CVE-2021-39009 [MEDIUM] CWE-312 CVE-2021-39009: IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 stores user credentials in plain clear text which ca IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 stores user credentials in plain clear text which can be read by a local privileged user. IBM X-Force ID: 213554.
nvd
CVE-2017-1784P4MEDIUMCVSS 5.5v11.0.0v11.0.1+10 more2018-01-29
CVE-2017-1784 [MEDIUM] CWE-200 CVE-2017-1784: IBM Cognos Analytics 11.0 could produce results in temporary files that contain highly sensitive inf IBM Cognos Analytics 11.0 could produce results in temporary files that contain highly sensitive information that can be read by a local user. IBM X-Force ID: 136858.
nvd
CVE-2021-39045P4MEDIUMCVSS 5.5≥ 11.1.0, < 11.1.7≥ 11.2.0, < 11.2.3+3 more2022-09-01
CVE-2021-39045 [MEDIUM] CWE-522 CVE-2021-39045: IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a local attacker to obtain information d IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a local attacker to obtain information due to the autocomplete feature on password input fields. IBM X-Force ID: 214345.
nvd
CVE-2024-45082P4MEDIUMCVSS 5.2≥ 11.2.0, ≤ 11.2.4≥ 12.0.0, ≤ 12.0.32024-12-18
CVE-2024-45082 [MEDIUM] CWE-601 CVE-2024-45082: IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 could allow a remote attacker IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would
nvd
CVE-2019-4722P4MEDIUMCVSS 4.3v11.0.0v11.1.0+2 more2021-06-01
CVE-2019-4722 [MEDIUM] CWE-755 CVE-2019-4722: IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain sensitive information via IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain sensitive information via a stack trace due to mishandling of certain error conditions. IBM X-Force ID: 172128.
nvd
CVE-2021-38905P4MEDIUMCVSS 4.3v11.1.7v11.2.0+1 more2022-04-22
CVE-2021-38905 [MEDIUM] CVE-2021-38905: IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 could allow an authenticated user to view report pag IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 could allow an authenticated user to view report pages that they should not have access to. IBM X-Force ID: 209697.
nvd
CVE-2023-32344P4MEDIUMCVSS 4.3≥ 11.1.1, < 11.1.7≥ 11.2.0, < 11.2.4+5 more2024-02-26
CVE-2023-32344 [MEDIUM] CWE-352 CVE-2023-32344: IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 is vulnerable to form action hijacking where it is p IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 is vulnerable to form action hijacking where it is possible to modify the form action to reference an arbitrary path. IBM X-Force ID: 255898.
nvd
CVE-2025-0917P4MEDIUMCVSS 4.8≥ 11.2.0, ≤ 11.2.4≥ 12.0.0, ≤ 12.0.4+10 more2025-06-11
CVE-2025-0917 [MEDIUM] CWE-79 CVE-2025-0917: IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12. IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session
nvd
CVE-2021-29824P4MEDIUMCVSS 4.3v11.1.7v11.2.0+1 more2022-04-22
CVE-2021-29824 [MEDIUM] CVE-2021-29824: IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to priviledge escalation where a lower IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to priviledge escalation where a lower level user could have read access to to the 'Data Connections' page to which they don't have access. IBM X-Force ID: 204468.
nvd
CVE-2019-4729P4MEDIUMCVSS 4.3≥ 11.0.0.0, < 11.0.13≥ 11.1.0, < 11.1.6+2 more2020-04-27
CVE-2019-4729 [MEDIUM] CWE-209 CVE-2019-4729: IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain sensitive information whe IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 172519.
nvd
CVE-2016-0398P4MEDIUMCVSS 4.3v11.0.02016-07-02
CVE-2016-0398 [MEDIUM] CWE-20 CVE-2016-0398: IBM Cognos Analytics (CA) 11.0 before 11.0.2 allows remote attackers to conduct content-spoofing att IBM Cognos Analytics (CA) 11.0 before 11.0.2 allows remote attackers to conduct content-spoofing attacks via a crafted URL.
nvd
CVE-2019-4231P4MEDIUMCVSS 4.3≥ 11.0.0, ≤ 11.0.12≥ 11.1.0, < 11.1.4.0+3 more2019-12-20
CVE-2019-4231 [MEDIUM] CWE-352 CVE-2019-4231: IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site request forgery which could allow an IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 159356.
nvd
Ibm Cognos Analytics vulnerabilities | cvebase