Show filters
100 Total Results
Displaying 71-80 of 100
Sort by:
Attacker Value
Unknown

CVE-2019-4589

Disclosure Date: July 30, 2020 (last updated February 21, 2025)
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to privlege escalation where the "My schedules and subscriptions" page is visible and accessible to a less privileged user. IBM X-Force ID: 167449.
Attacker Value
Unknown

CVE-2019-4366

Disclosure Date: July 30, 2020 (last updated November 28, 2024)
IBM Cognos Analytics 11.0 and 11.1 is susceptible to an information disclosure vulnerability where an attacker could gain access to cached browser data. IBM X-Force ID: 161748.
Attacker Value
Unknown

CVE-2020-4377

Disclosure Date: July 30, 2020 (last updated February 21, 2025)
IBM Cognos Anaytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 179156.
Attacker Value
Unknown

CVE-2019-4729

Disclosure Date: April 24, 2020 (last updated February 21, 2025)
IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 172519.
Attacker Value
Unknown

CVE-2019-4623

Disclosure Date: December 30, 2019 (last updated November 27, 2024)
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 168924.
Attacker Value
Unknown

CVE-2019-4343

Disclosure Date: December 30, 2019 (last updated November 27, 2024)
IBM Cognos Analytics 11.0 and 11.1 allows overly permissive cross-origin resource sharing which could allow an attacker to transfer private information. An attacker could exploit this vulnerability to access content that should be restricted. IBM X-Force ID: 161422.
Attacker Value
Unknown

CVE-2019-4555

Disclosure Date: December 20, 2019 (last updated November 27, 2024)
IBM Cognos Analytics 11.0 and 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 166204.
Attacker Value
Unknown

CVE-2019-4231

Disclosure Date: December 20, 2019 (last updated November 27, 2024)
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 159356.
Attacker Value
Unknown

CVE-2019-4334

Disclosure Date: November 09, 2019 (last updated November 27, 2024)
IBM Cognos Analytics 11.0 and 11.1 could reveal sensitive information to an authenticated user that could be used in future attacks against the system. IBM X-Force ID: 161271.
Attacker Value
Unknown

CVE-2018-1721

Disclosure Date: November 09, 2019 (last updated November 27, 2024)
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or cause the web server to make HTTP requests to arbitrary domains. IBM X-Force ID: 147369.