cbcvebase.

Ibm Cognos Controller vulnerabilities

52 known vulnerabilities affecting ibm/cognos_controller.

Total CVEs
52
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH16MEDIUM24LOW6

Vulnerabilities

Page 2 of 3
CVE-2020-4685P3HIGHCVSS 7.2v10.3.0v10.3.1+3 more2020-11-11
CVE-2020-4685 [HIGH] CVE-2020-4685: A low level user of IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, 10.4.1, and 10.4.2 who has Adminis A low level user of IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, 10.4.1, and 10.4.2 who has Administration rights to the server where the application is installed, can escalate their privilege from Low level to Super Admin and gain access to Create/Update/Delete any level of user in Cognos Controller. IBM X-Force ID: 186625.
nvd
CVE-2024-28778P3MEDIUMCVSS 6.5≥ 11.0.0, ≤ 11.0.12025-01-07
CVE-2024-28778 [MEDIUM] CWE-798 CVE-2024-28778: IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 is vulnerable to exposure of A IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 is vulnerable to exposure of Artifactory API keys. This vulnerability allows users to publish code to private packages or repositories under the name of the organization.
nvd
CVE-2019-4175P3HIGHCVSS 7.5v10.4.0v10.4.1+2 more2019-09-17
CVE-2019-4175 [HIGH] CWE-326 CVE-2019-4175: IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, and 10.4.1 uses weaker than expected cryptographic alg IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, and 10.4.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 158880.
nvd
CVE-2019-4173P3MEDIUMCVSS 6.5v10.2.0v10.2.1+3 more2019-06-17
CVE-2019-4173 [MEDIUM] CWE-200 CVE-2019-4173: IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 could allow a remote attacker to ob IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 could allow a remote attacker to obtain sensitive information, caused by a flaw in the HTTP OPTIONS method, aka Optionsbleed. By sending an OPTIONS HTTP request, a remote attacker could exploit this vulnerability to read secret data from process memory and obtain sensitive information. I
nvd
CVE-2024-45081P3MEDIUMCVSS 6.5≥ 11.0.0, < 11.0.1.4≥ 11.0.0, ≤ 11.0.12025-02-19
CVE-2024-45081 [MEDIUM] CWE-863 CVE-2024-45081: IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 could allow an authent IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 could allow an authenticated user to modify restricted content due to incorrect authorization checks.
nvd
CVE-2025-33079P4MEDIUMCVSS 6.5v11.0.0v11.0.1+1 more2025-05-27
CVE-2025-33079 [MEDIUM] CWE-256 CVE-2025-33079: IBM Controller 11.0.0, 11.0.1, and 11.1.0 application could allow an authenticated user to obtain se IBM Controller 11.0.0, 11.0.1, and 11.1.0 application could allow an authenticated user to obtain sensitive credentials that may be inadvertently included within the source code.
nvd
CVE-2025-36015P4MEDIUMCVSS 6.5≥ 11.0.0, < 11.0.1.7≥ 11.0.0, ≤ 11.0.1 FP62025-12-08
CVE-2025-36015 [MEDIUM] CWE-1284 CVE-2025-36015: IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 could allow IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 could allow an authenticated user to cause a denial of service due to improper validation of a specified quantity size input.
nvd
CVE-2024-41776P4MEDIUMCVSS 6.5v11.0.0v11.0.1+1 more2024-12-03
CVE-2024-41776 [MEDIUM] CWE-352 CVE-2024-41776: IBM Cognos Controller 11.0.0 and 11.0.1 is vulnerable to cross-site request forgery whic IBM Cognos Controller 11.0.0 and 11.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
nvd
CVE-2019-4176P4MEDIUMCVSS 5.3v10.2.0v10.2.1+3 more2019-06-17
CVE-2019-4176 [MEDIUM] CVE-2019-4176: IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 could allow a remote attacker to by IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 could allow a remote attacker to bypass security restrictions, caused by an error related to insecure HTTP Methods. An attacker could exploit this vulnerability to gain access to the system. IBM X-Force ID: 158881.
nvd
CVE-2024-28780P4MEDIUMCVSS 5.9≥ 11.0.0, < 11.0.1.4≥ 11.0.0, ≤ 11.0.12025-02-19
CVE-2024-28780 [MEDIUM] CWE-327 CVE-2024-28780: IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 Rich Client uses wea IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 Rich Client uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
nvd
CVE-2022-22364P4MEDIUMCVSS 5.3v10.4.1v10.4.2+2 more2024-05-03
CVE-2022-22364 [MEDIUM] CWE-350 CVE-2022-22364: IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to external service interaction attac IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to external service interaction attack, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to induce the application to perform server-side DNS lookups or HTTP requests to arbitrary domain names. By submitting suitable payloads, an at
nvd
CVE-2021-29892P4MEDIUMCVSS 5.9v11.0.0v11.0.1+1 more2024-12-03
CVE-2021-29892 [MEDIUM] CWE-319 CVE-2021-29892: IBM Cognos Controller 11.0.0 and 11.0.1 could allow a remote attacker to obtain sensitive informatio IBM Cognos Controller 11.0.0 and 11.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
nvd
CVE-2023-23474P4MEDIUMCVSS 5.3v10.4.1v10.4.2+2 more2024-05-03
CVE-2023-23474 [MEDIUM] CWE-209 CVE-2023-23474: IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 could allow a remote attacker to obtain sensitive i IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser. IBM X-Force ID: 245403.
nvd
CVE-2024-25035P4MEDIUMCVSS 5.3v11.0.0v11.0.1+1 more2024-12-03
CVE-2024-25035 [MEDIUM] CWE-497 CVE-2024-25035: IBM Cognos Controller 11.0.0 and 11.0.1 exposes server details that could allow an attacker to o IBM Cognos Controller 11.0.0 and 11.0.1 exposes server details that could allow an attacker to obtain information of the application environment to conduct further attacks.
nvd
CVE-2024-28776P4MEDIUMCVSS 5.4≥ 11.0.0, < 11.0.1.4≥ 11.0.0, ≤ 11.0.12025-02-19
CVE-2024-28776 [MEDIUM] CWE-79 CVE-2024-28776: IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to cross-s IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2021-20556P4MEDIUMCVSS 5.3v10.4.1v10.4.2+2 more2024-05-03
CVE-2021-20556 [MEDIUM] CWE-204 CVE-2021-20556: IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 could allow a remote user to enumerate usernames du IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 could allow a remote user to enumerate usernames due to differentiating error messages on existing usernames. IBM X-Force ID: 199181.
nvd
CVE-2023-28952P4MEDIUMCVSS 5.3v10.4.1v10.4.2+2 more2024-05-03
CVE-2023-28952 [MEDIUM] CWE-117 CVE-2023-28952: IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to injection attacks in application l IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to injection attacks in application logging by not sanitizing user provided data. IBM X-Force ID: 251463.
nvd
CVE-2019-4412P4MEDIUMCVSS 5.3v10.3.0v10.3.1+2 more2019-11-09
CVE-2019-4412 [MEDIUM] CWE-200 CVE-2019-4412: IBM Cognos Controller stores sensitive information in URL parameters. This may lead to information d IBM Cognos Controller stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 162659.
nvd
CVE-2019-4136P4MEDIUMCVSS 5.4v10.2.0v10.2.1+3 more2019-06-17
CVE-2019-4136 [MEDIUM] CWE-79 CVE-2019-4136: IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 is vulnerable to cross-site scripti IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 158332.
nvd
CVE-2025-33111P4MEDIUMCVSS 4.3≥ 11.0.0, < 11.0.1.7≥ 11.0.0, ≤ 11.0.1 FP62025-12-08
CVE-2025-33111 [MEDIUM] CWE-379 CVE-2025-33111: IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 is vulnerab IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 is vulnerable to creation of temporary files without atomic operations which may expose sensitive information to an authenticated user due to race condition attacks.
nvd
Ibm Cognos Controller vulnerabilities | cvebase