Ibm Cognos Analytics Mobile vulnerabilities

10 known vulnerabilities affecting ibm/cognos_analytics_mobile.

Total CVEs
10
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH4MEDIUM5LOW1

Vulnerabilities

Page 1 of 1
CVE-2025-36062HIGHCVSS 7.5≥ 1.1.0, < 1.1.23≥ 1.1.0, ≤ 1.1.222025-07-21
CVE-2025-36062 [MEDIUM] CWE-311 CVE-2025-36062: IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 could be vulnerable to information exposure IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 could be vulnerable to information exposure due to the use of unencrypted network traffic.
cvelistv5nvd
CVE-2025-36107HIGHCVSS 7.5≥ 1.1.0, < 1.1.23≥ 1.1.0, ≤ 1.1.222025-07-21
CVE-2025-36107 [MEDIUM] CWE-319 CVE-2025-36107: IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 could allow malicious actors to obtain sensit IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 could allow malicious actors to obtain sensitive information due to the cleartext transmission of data.
cvelistv5nvd
CVE-2025-36106HIGHCVSS 8.2≥ 1.1.0, < 1.1.23≥ 1.1.0, ≤ 1.1.222025-07-21
CVE-2025-36106 [MEDIUM] CWE-326 CVE-2025-36106: IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 could allow malicious actors to view and modi IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 could allow malicious actors to view and modify information coming to and from the application which could then be used to access confidential information on the device or network by using a the deprecated or misconfigured AFNetworking library at runtime.
cvelistv5nvd
CVE-2025-36057MEDIUMCVSS 4.6≥ 1.1.0, < 1.1.23≥ 1.1.0, ≤ 1.1.222025-07-21
CVE-2025-36057 [MEDIUM] CWE-299 CVE-2025-36057: IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 is vulnerable to authentication bypass by u IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 is vulnerable to authentication bypass by using the Local Authentication Framework library which is not needed as biometric authentication is not used in the application.
cvelistv5nvd
CVE-2024-55907MEDIUMCVSS 5.3≥ 1.1.0, < 1.1.21v1.12025-03-02
CVE-2024-55907 [LOW] CWE-540 CVE-2024-55907: IBM Cognos Analytics Mobile 1.1 for iOS application could allow an attacker to reverse engineer the IBM Cognos Analytics Mobile 1.1 for iOS application could allow an attacker to reverse engineer the codebase to gain knowledge about the programming technique, interface, class definitions, algorithms and functions used due to weak obfuscation.
cvelistv5nvd
CVE-2025-0895LOWCVSS 2.4≥ 1.1.0, < 1.1.21v1.12025-03-02
CVE-2025-0895 [LOW] CWE-215 CVE-2025-0895: IBM Cognos Analytics Mobile 1.1 for Android could allow a user with physical access to the device, t IBM Cognos Analytics Mobile 1.1 for Android could allow a user with physical access to the device, to obtain sensitive information from debugging code log messages.
cvelistv5nvd
CVE-2023-38009MEDIUMCVSS 5.9v1.12025-01-26
CVE-2023-38009 [MEDIUM] CWE-295 CVE-2023-38009: IBM Cognos Mobile Client 1.1 iOS may be vulnerable to information disclosure through man in the midd IBM Cognos Mobile Client 1.1 iOS may be vulnerable to information disclosure through man in the middle techniques due to the lack of certificate pinning.
cvelistv5nvd
CVE-2021-39081HIGHCVSS 7.5v1.1.142024-12-19
CVE-2021-39081 [MEDIUM] CWE-319 CVE-2021-39081: IBM Cognos Analytics Mobile for Android 1.1.14 uses weaker than expected cryptographic algorithms th IBM Cognos Analytics Mobile for Android 1.1.14 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
nvd
CVE-2021-39080MEDIUMCVSS 6.5≥ 1.1.0, < 1.1.14v1.12022-02-14
CVE-2021-39080 [MEDIUM] CVE-2021-39080: Due to weak obfuscation, IBM Cognos Analytics Mobile for Android application prior to version 1.1.14 Due to weak obfuscation, IBM Cognos Analytics Mobile for Android application prior to version 1.1.14 , an attacker could be able to reverse engineer the codebase to gain knowledge about the programming technique, interface, class definitions, algorithms and functions used. IBM X-Force ID: 215593.
cvelistv5nvd
CVE-2021-39079MEDIUMCVSS 5.4fixed in 1.1.14v1.12022-02-14
CVE-2021-39079 [MEDIUM] CWE-79 CVE-2021-39079: IBM Cognos Analytics Mobile for Android applications prior to version 1.1.14 is vulnerable to cross- IBM Cognos Analytics Mobile for Android applications prior to version 1.1.14 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 215592.
cvelistv5nvd