Ibm Cognos Controller vulnerabilities
52 known vulnerabilities affecting ibm/cognos_controller.
Total CVEs
52
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH16MEDIUM24LOW6
Vulnerabilities
Page 1 of 3
CVE-2023-38724P3CRITICALCVSS 9.8v10.4.1v10.4.2+2 more2024-05-03
CVE-2023-38724 [CRITICAL] CWE-89 CVE-2023-38724: IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to SQL injection. A remote attacker c
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 262183.
nvd
CVE-2024-25020P3CRITICALCVSS 9.8v11.0.0v11.0.1+1 more2024-12-03
CVE-2024-25020 [CRITICAL] CWE-434 CVE-2024-25020: IBM Cognos Controller 11.0.0 and 11.0.1 is vulnerable to malicious file upload by allo
IBM Cognos Controller 11.0.0 and 11.0.1
is vulnerable to malicious file upload by allowing unrestricted filetype attachments in the Journal entry page. Attackers can make use of this weakness and upload malicious executable files into the system and can be sent to victims for performing further attacks.
nvd
CVE-2024-40691P3CRITICALCVSS 9.8v11.0.0v11.0.1+1 more2024-12-03
CVE-2024-40691 [CRITICAL] CWE-434 CVE-2024-40691: IBM Cognos Controller 11.0.0 and 11.0.1 could be vulnerable to malicious file upload by not valida
IBM Cognos Controller 11.0.0 and 11.0.1
could be vulnerable to malicious file upload by not validating the content of the file uploaded to the web interface. Attackers can make use of this weakness and upload malicious executable files into the system, and it can be sent to victim for performing further attacks.
nvd
CVE-2024-25019P3CRITICALCVSS 9.8v11.0.0v11.0.1+1 more2024-12-03
CVE-2024-25019 [CRITICAL] CWE-434 CVE-2024-25019: IBM Cognos Controller 11.0.0 and 11.0.1 could be vulnerable to malicious file upload by not valida
IBM Cognos Controller 11.0.0 and 11.0.1
could be vulnerable to malicious file upload by not validating the type of file uploaded to Journal entry attachments. Attackers can make use of this weakness and upload malicious executable files into the system that can be sent to victims for performing further attacks.
nvd
CVE-2024-28777P3HIGHCVSS 8.8≥ 11.0.0, < 11.0.1.4≥ 11.0.0, ≤ 11.0.12025-02-19
CVE-2024-28777 [HIGH] CWE-502 CVE-2024-28777: IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to unres
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0
is vulnerable to unrestricted deserialization. This vulnerability allows users to execute arbitrary code, escalate privileges, or cause denial of service attacks by exploiting the unrestricted deserialization of types in the application.
nvd
CVE-2020-4879P3CRITICALCVSS 9.8v10.4.0v10.4.1+1 more2022-01-21
CVE-2020-4879 [CRITICAL] CWE-287 CVE-2020-4879: IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could allow a remote attacker to bypass security re
IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could allow a remote attacker to bypass security restrictions, caused by improper validation of authentication cookies. IBM X-Force ID: 190847.
nvd
CVE-2024-52902P3HIGHCVSS 8.8≥ 11.0.0, < 11.0.1.4≥ 11.0.0, ≤ 11.0.12025-02-19
CVE-2024-52902 [HIGH] CWE-798 CVE-2024-52902: IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 client application contain
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 client application contains hard coded database passwords in source code which could be used for unauthorized access to the system.
nvd
CVE-2020-4876P3HIGHCVSS 8.2v10.4.0v10.4.1+1 more2022-01-21
CVE-2020-4876 [HIGH] CWE-611 CVE-2020-4876: IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 is vulnerable to an XML External Entity Injection (
IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 190839.
nvd
CVE-2020-4875P3HIGHCVSS 8.2v10.4.0v10.4.1+1 more2022-01-21
CVE-2020-4875 [HIGH] CWE-611 CVE-2020-4875: IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 is vulnerable to an XML External Entity Injection (
IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 190838.
nvd
CVE-2023-47160P3HIGHCVSS 8.2≥ 11.0.0, < 11.0.1.4≥ 11.0.0, ≤ 11.0.12025-02-19
CVE-2023-47160 [HIGH] CWE-611 CVE-2023-47160: IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to an
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0
is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
nvd
CVE-2023-40695P3HIGHCVSS 8.8v10.4.1v10.4.2+2 more2024-05-03
CVE-2023-40695 [HIGH] CWE-613 CVE-2023-40695: IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 does not invalidate session after logout which coul
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 264938.
nvd
CVE-2020-4877P3CRITICALCVSS 9.8v10.4.0v10.4.1+1 more2022-01-21
CVE-2020-4877 [CRITICAL] CWE-863 CVE-2020-4877: IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could be vulnerable to unauthorized modifications b
IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could be vulnerable to unauthorized modifications by using public fields in public classes. IBM X-Force ID: 190843.
nvd
CVE-2024-45084P3HIGHCVSS 8.0≥ 11.0.0, < 11.0.1.4≥ 11.0.0, ≤ 11.0.12025-02-19
CVE-2024-45084 [HIGH] CWE-1236 CVE-2024-45084: IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 could allow an authentic
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0
could allow an authenticated attacker to conduct formula injection. An attacker could execute arbitrary commands on the system, caused by improper validation of file contents.
nvd
CVE-2024-40702P3HIGHCVSS 8.2≥ 11.0.0, ≤ 11.0.12025-01-07
CVE-2024-40702 [HIGH] CWE-295 CVE-2024-40702: IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow an unauthorized us
IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow an unauthorized user to obtain valid tokens to gain access to protected resources due to improper certificate validation.
nvd
CVE-2024-41777P3HIGHCVSS 7.5v11.0.0v11.0.1+1 more2024-12-03
CVE-2024-41777 [HIGH] CWE-798 CVE-2024-41777: IBM Cognos Controller 11.0.0 and 11.0.1 contains hard-coded credentials, such as a passwor
IBM Cognos Controller 11.0.0 and 11.0.1
contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
nvd
CVE-2021-20451P3HIGHCVSS 7.2v10.4.1v10.4.2+2 more2024-05-03
CVE-2021-20451 [HIGH] CWE-89 CVE-2021-20451: IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to SQL injection. A remote attacker c
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 196643.
nvd
CVE-2025-36326P3HIGHCVSS 7.5≥ 11.0.0, ≤ 11.0.12025-09-26
CVE-2025-36326 [HIGH] CWE-321 CVE-2025-36326: IBM Cognos Controller 11.0.0 through 11.0.1, and IBM Controller 11.1.0 through 11.1.1 could allow an
IBM Cognos Controller 11.0.0 through 11.0.1, and IBM Controller 11.1.0 through 11.1.1 could allow an attacker to obtain sensitive information due to the use of hardcoded cryptographic keys for signing session cookies.
nvd
CVE-2020-4874P3HIGHCVSS 7.5v10.4.1v10.4.2+2 more2024-05-03
CVE-2020-4874 [HIGH] CWE-327 CVE-2020-4874: IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 uses weaker than expected cryptographic algorithms
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 190837.
nvd
CVE-2023-40696P3HIGHCVSS 7.5v10.4.1v10.4.2+2 more2024-05-03
CVE-2023-40696 [HIGH] CWE-327 CVE-2023-40696: IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 uses weaker than expected cryptographic algorithms
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 264939.
nvd
CVE-2024-41775P3HIGHCVSS 7.5v11.0.0v11.0.1+1 more2024-12-03
CVE-2024-41775 [HIGH] CWE-327 CVE-2024-41775: IBM Cognos Controller 11.0.0 and 11.0.1 uses weaker than expected cryptographic algorithms that coul
IBM Cognos Controller 11.0.0 and 11.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
nvd
1 / 3Next →