Show filters
42 Total Results
Displaying 11-20 of 42
Sort by:
Attacker Value
Unknown
CVE-2022-43883
Disclosure Date: December 19, 2022 (last updated November 08, 2023)
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could be vulnerable to a Log Injection attack by constructing URLs from user-controlled data. This could enable attackers to make arbitrary requests to the internal network or to the local file system. IBM X-Force ID: 240266.
0
Attacker Value
Unknown
CVE-2022-39160
Disclosure Date: December 19, 2022 (last updated November 08, 2023)
IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 235064.
0
Attacker Value
Unknown
CVE-2022-38708
Disclosure Date: December 19, 2022 (last updated November 08, 2023)
IBM Cognos Analytics 11.1.7 11.2.0, and 11.2.1 could be vulnerable to a Server-Side Request Forgery Attack (SSRF) attack by constructing URLs from user-controlled data. This could enable attackers to make arbitrary requests to the internal network or to the local file system. IBM X-Force ID: 234180.
0
Attacker Value
Unknown
CVE-2022-34339
Disclosure Date: November 03, 2022 (last updated December 22, 2024)
"IBM Cognos Analytics 11.2.1, 11.2.0, 11.1.7 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 229963."
0
Attacker Value
Unknown
CVE-2020-4301
Disclosure Date: August 31, 2022 (last updated December 22, 2024)
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 176609.
0
Attacker Value
Unknown
CVE-2021-39009
Disclosure Date: August 31, 2022 (last updated November 29, 2024)
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 stores user credentials in plain clear text which can be read by a local privileged user. IBM X-Force ID: 213554.
0
Attacker Value
Unknown
CVE-2021-39045
Disclosure Date: August 31, 2022 (last updated November 29, 2024)
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a local attacker to obtain information due to the autocomplete feature on password input fields. IBM X-Force ID: 214345.
0
Attacker Value
Unknown
CVE-2021-20468
Disclosure Date: August 31, 2022 (last updated November 29, 2024)
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 196825.
0
Attacker Value
Unknown
CVE-2022-30614
Disclosure Date: August 31, 2022 (last updated November 29, 2024)
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to a denial of service via email flooding caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume all available CPU resources. IBM X-Force ID: 227591.
0
Attacker Value
Unknown
CVE-2022-36773
Disclosure Date: August 31, 2022 (last updated November 29, 2024)
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 233571.
0