Show filters
100 Total Results
Displaying 61-70 of 100
Sort by:
Attacker Value
Unknown
CVE-2020-4561
Disclosure Date: May 28, 2021 (last updated February 22, 2025)
IBM Cognos Analytics 11.0 and 11.1 DQM API allows submitting of all control requests in unauthenticated sessions. This allows a remote attacker who can access a valid CA endpoint to read and write files to the Cognos Analytics system. IBM X-Force ID: 183903.
0
Attacker Value
Unknown
CVE-2019-4730
Disclosure Date: May 28, 2021 (last updated February 22, 2025)
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 172533.
0
Attacker Value
Unknown
CVE-2020-4354
Disclosure Date: May 28, 2021 (last updated February 22, 2025)
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 178506.
0
Attacker Value
Unknown
CVE-2019-4653
Disclosure Date: May 28, 2021 (last updated February 22, 2025)
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 170964.
0
Attacker Value
Unknown
CVE-2019-4724
Disclosure Date: May 28, 2021 (last updated February 22, 2025)
IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain credentials from a user's browser via incorrect autocomplete settings in New Content Backup page. IBM X-Force ID: 172130.
0
Attacker Value
Unknown
CVE-2020-4300
Disclosure Date: May 28, 2021 (last updated February 22, 2025)
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 176607.
0
Attacker Value
Unknown
CVE-2019-4471
Disclosure Date: May 28, 2021 (last updated February 22, 2025)
IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain sensitive information, caused by the failure to set the secure flag for a sensitive cookie in an HTTPS session. A remote attacker could exploit this vulnerability to obtain sensitive information. IBM X-Force ID: 163780.
0
Attacker Value
Unknown
CVE-2019-4723
Disclosure Date: May 28, 2021 (last updated February 22, 2025)
IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain credentials from a user's browser via incorrect autocomplete settings in New Data Server Connection page. IBM X-Force ID: 172129.
0
Attacker Value
Unknown
CVE-2020-4388
Disclosure Date: October 09, 2020 (last updated February 22, 2025)
IBM Cognos Analytics 11.0 and 11.1 could be vulnerable to a denial of service attack by failing to catch exceptions in a servlet also exposing debug information could also be used in future attacks. IBM X-Force ID: 179270.
0
Attacker Value
Unknown
CVE-2020-4302
Disclosure Date: October 09, 2020 (last updated February 22, 2025)
IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to execute arbitrary code on the system, caused by a CSV injection. By persuading a victim to open a specially-crafted excel file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 176610.
0