Show filters
100 Total Results
Displaying 51-60 of 100
Sort by:
Attacker Value
Unknown

CVE-2021-20493

Disclosure Date: December 02, 2021 (last updated February 23, 2025)
IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 197794.
Attacker Value
Unknown

CVE-2021-29867

Disclosure Date: December 02, 2021 (last updated October 07, 2023)
IBM Cognos Analytics 11.1.7 and 11.2.0 could allow an authenticated to view or edit a Jupyter notebook that they should not have access to. IBM X-Force ID: 206212.
Attacker Value
Unknown

CVE-2021-29756

Disclosure Date: December 02, 2021 (last updated February 23, 2025)
IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site request forgery (CSRF) in the My Inbox page which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 202167.
Attacker Value
Unknown

CVE-2021-20470

Disclosure Date: December 02, 2021 (last updated February 23, 2025)
IBM Cognos Analytics 11.1.7 and 11.2.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 196339.
Attacker Value
Unknown

CVE-2020-4951

Disclosure Date: October 14, 2021 (last updated February 23, 2025)
IBM Cognos Analytics 11.1.7 and 11.2.0 contains locally cached browser data, that could allow a local attacker to obtain sensitive information.
Attacker Value
Unknown

CVE-2021-29679

Disclosure Date: October 14, 2021 (last updated February 23, 2025)
IBM Cognos Analytics 11.1.7 and 11.2.0 could allow an authenticated user to execute code remotely due to incorrectly neutralizaing user-contrlled input that could be interpreted a a server-side include (SSI) directive. IBM X-Force ID: 199915.
Attacker Value
Unknown

CVE-2021-29745

Disclosure Date: October 14, 2021 (last updated November 28, 2024)
IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to priviledge escalation where a lower evel user could have access to the 'New Job' page to which they should not have access to. IBM X-Force ID: 201695.
Attacker Value
Unknown

CVE-2021-20461

Disclosure Date: June 29, 2021 (last updated February 22, 2025)
IBM Cognos Analytics 10.0 and 11.1 is susceptible to a weakness in the implementation of the System Appearance configuration setting. An attacker could potentially bypass business logic to modify the appearance and behavior of the application. IBM X-Force ID: 196770.
Attacker Value
Unknown

CVE-2019-4722

Disclosure Date: May 28, 2021 (last updated February 22, 2025)
IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain sensitive information via a stack trace due to mishandling of certain error conditions. IBM X-Force ID: 172128.
Attacker Value
Unknown

CVE-2020-4520

Disclosure Date: May 28, 2021 (last updated February 22, 2025)
IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to inject malicious HTML code that when viewed by the authenticated victim would execute the code. IBM X-Force ID: 182395.