Show filters
100 Total Results
Displaying 41-50 of 100
Sort by:
Attacker Value
Unknown
CVE-2021-29824
Disclosure Date: April 21, 2022 (last updated October 07, 2023)
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to priviledge escalation where a lower level user could have read access to to the 'Data Connections' page to which they don't have access. IBM X-Force ID: 204468.
0
Attacker Value
Unknown
CVE-2021-20464
Disclosure Date: April 21, 2022 (last updated October 07, 2023)
IBM Cognos Analytics PowerPlay (IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7) could be vulnerable to an XML Bomb attack by a malicious authenticated user. IBM X-Force ID: 196813.
0
Attacker Value
Unknown
CVE-2021-38946
Disclosure Date: April 21, 2022 (last updated October 07, 2023)
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 211240.
0
Attacker Value
Unknown
CVE-2021-38886
Disclosure Date: April 21, 2022 (last updated October 07, 2023)
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 209399.
0
Attacker Value
Unknown
CVE-2021-38905
Disclosure Date: April 21, 2022 (last updated October 07, 2023)
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 could allow an authenticated user to view report pages that they should not have access to. IBM X-Force ID: 209697.
0
Attacker Value
Unknown
CVE-2021-39080
Disclosure Date: February 11, 2022 (last updated October 07, 2023)
Due to weak obfuscation, IBM Cognos Analytics Mobile for Android application prior to version 1.1.14 , an attacker could be able to reverse engineer the codebase to gain knowledge about the programming technique, interface, class definitions, algorithms and functions used. IBM X-Force ID: 215593.
0
Attacker Value
Unknown
CVE-2021-39079
Disclosure Date: February 11, 2022 (last updated February 23, 2025)
IBM Cognos Analytics Mobile for Android applications prior to version 1.1.14 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 215592.
0
Attacker Value
Unknown
CVE-2021-29716
Disclosure Date: December 02, 2021 (last updated October 07, 2023)
IBM Cognos Analytics 11.1.7 and 11.2.0 could allow a low level user to reas of the application that privileged user should only be allowed to view. IBM X-Force ID: 201087.
0
Attacker Value
Unknown
CVE-2021-38909
Disclosure Date: December 02, 2021 (last updated February 23, 2025)
IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 209706.
0
Attacker Value
Unknown
CVE-2021-29719
Disclosure Date: December 02, 2021 (last updated October 07, 2023)
IBM Cognos Analytics 11.1.7 and 11.2.0 could be vulnerable to client side vulnerabilties due to a web response specifying an incorrect content type. IBM X-Force ID: 201091
0