Show filters
100 Total Results
Displaying 21-30 of 100
Sort by:
Attacker Value
Unknown

CVE-2023-25929

Disclosure Date: July 22, 2023 (last updated October 08, 2023)
IBM Cognos Analytics 11.1 and 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 247861.
Attacker Value
Unknown

CVE-2023-28953

Disclosure Date: July 10, 2023 (last updated October 08, 2023)
IBM Cognos Analytics on Cloud Pak for Data 4.0 could allow an attacker to make system calls that might compromise the security of the containers due to misconfigured security context. IBM X-Force ID: 251465.
Attacker Value
Unknown

CVE-2021-39036

Disclosure Date: May 12, 2023 (last updated October 08, 2023)
IBM Cognos Analytics 11.1 and 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 213966.
Attacker Value
Unknown

CVE-2022-43887

Disclosure Date: December 19, 2022 (last updated November 08, 2023)
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could be vulnerable to sensitive information exposure by passing API keys to log files. If these keys contain sensitive information, it could lead to further attacks. IBM X-Force ID: 240450.
Attacker Value
Unknown

CVE-2022-43883

Disclosure Date: December 19, 2022 (last updated November 08, 2023)
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could be vulnerable to a Log Injection attack by constructing URLs from user-controlled data. This could enable attackers to make arbitrary requests to the internal network or to the local file system. IBM X-Force ID: 240266.
Attacker Value
Unknown

CVE-2022-39160

Disclosure Date: December 19, 2022 (last updated November 08, 2023)
IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 235064.
Attacker Value
Unknown

CVE-2022-38708

Disclosure Date: December 19, 2022 (last updated November 08, 2023)
IBM Cognos Analytics 11.1.7 11.2.0, and 11.2.1 could be vulnerable to a Server-Side Request Forgery Attack (SSRF) attack by constructing URLs from user-controlled data. This could enable attackers to make arbitrary requests to the internal network or to the local file system. IBM X-Force ID: 234180.
Attacker Value
Unknown

CVE-2022-34339

Disclosure Date: November 03, 2022 (last updated December 22, 2024)
"IBM Cognos Analytics 11.2.1, 11.2.0, 11.1.7 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 229963."
Attacker Value
Unknown

CVE-2020-4301

Disclosure Date: August 31, 2022 (last updated December 22, 2024)
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 176609.
Attacker Value
Unknown

CVE-2021-39009

Disclosure Date: August 31, 2022 (last updated November 29, 2024)
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 stores user credentials in plain clear text which can be read by a local privileged user. IBM X-Force ID: 213554.