Show filters
100 Total Results
Displaying 31-40 of 100
Sort by:
Attacker Value
Unknown

CVE-2021-39045

Disclosure Date: August 31, 2022 (last updated November 29, 2024)
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a local attacker to obtain information due to the autocomplete feature on password input fields. IBM X-Force ID: 214345.
Attacker Value
Unknown

CVE-2021-20468

Disclosure Date: August 31, 2022 (last updated November 29, 2024)
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 196825.
Attacker Value
Unknown

CVE-2022-30614

Disclosure Date: August 31, 2022 (last updated November 29, 2024)
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to a denial of service via email flooding caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume all available CPU resources. IBM X-Force ID: 227591.
Attacker Value
Unknown

CVE-2022-36773

Disclosure Date: August 31, 2022 (last updated November 29, 2024)
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 233571.
Attacker Value
Unknown

CVE-2021-29823

Disclosure Date: August 31, 2022 (last updated November 29, 2024)
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 204465.
Attacker Value
Unknown

CVE-2021-29768

Disclosure Date: June 22, 2022 (last updated November 29, 2024)
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a low level user to obtain sensitive information from the details of the 'Cloud Storage' page for which they should not have access. IBM X-Force ID: 202682.
Attacker Value
Unknown

CVE-2021-39047

Disclosure Date: June 22, 2022 (last updated November 29, 2024)
IBM Planning Analytics 2.0 and IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 214349.
Attacker Value
Unknown

CVE-2021-38945

Disclosure Date: June 22, 2022 (last updated November 29, 2024)
IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 could allow a remote attacker to upload arbitrary files, caused by improper content validation. IBM X-Force ID: 211238.
Attacker Value
Unknown

CVE-2021-38904

Disclosure Date: April 21, 2022 (last updated October 07, 2023)
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 could allow a remote attacker to obtain credentials from a user's browser via incorrect autocomplete settings. IBM X-Force ID: 209693.
Attacker Value
Unknown

CVE-2021-38903

Disclosure Date: April 21, 2022 (last updated October 07, 2023)
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials. IBM X-Force ID: 209691.