Ibm Cognos Analytics vulnerabilities
105 known vulnerabilities affecting ibm/cognos_analytics.
Total CVEs
105
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH24MEDIUM73LOW2
Vulnerabilities
Page 6 of 6
CVE-2019-4589P4MEDIUMCVSS 4.3v11.0.0v11.1.0+2 more2020-08-03
CVE-2019-4589 [MEDIUM] CWE-269 CVE-2019-4589: IBM Cognos Analytics 11.0 and 11.1 is vulnerable to privlege escalation where the "My schedules and
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to privlege escalation where the "My schedules and subscriptions" page is visible and accessible to a less privileged user. IBM X-Force ID: 167449.
nvd
CVE-2019-4334P4MEDIUMCVSS 4.3v11.0.0v11.1.0+2 more2019-11-09
CVE-2019-4334 [MEDIUM] CVE-2019-4334: IBM Cognos Analytics 11.0 and 11.1 could reveal sensitive information to an authenticated user that
IBM Cognos Analytics 11.0 and 11.1 could reveal sensitive information to an authenticated user that could be used in future attacks against the system. IBM X-Force ID: 161271.
nvd
CVE-2017-1783P4MEDIUMCVSS 4.0v11.0.0v11.0.1+10 more2018-01-29
CVE-2017-1783 [MEDIUM] CWE-287 CVE-2017-1783: IBM Cognos Analytics 11.0 could allow a local user to change parameters set from the Cognos Analytic
IBM Cognos Analytics 11.0 could allow a local user to change parameters set from the Cognos Analytics menus without proper authentication. IBM X-Force ID: 136857.
nvd
CVE-2018-1842P4LOWCVSS 3.6≥ 11.0.0.0, ≤ 11.0.12.0v112018-11-09
CVE-2018-1842 [LOW] CWE-347 CVE-2018-1842: IBM Cognos Analytics 11 Configuration tool, under certain circumstances, will bypass OIDC namespace
IBM Cognos Analytics 11 Configuration tool, under certain circumstances, will bypass OIDC namespace signature verification on its id_token. IBM X-Force ID: 150902.
nvd
CVE-2020-4951P4LOWCVSS 3.3v11.1.7v11.2.02021-10-15
CVE-2020-4951 [LOW] CWE-200 CVE-2020-4951: IBM Cognos Analytics 11.1.7 and 11.2.0 contains locally cached browser data, that could allow a loca
IBM Cognos Analytics 11.1.7 and 11.2.0 contains locally cached browser data, that could allow a local attacker to obtain sensitive information.
nvd
← Previous6 / 6