Show filters
100 Total Results
Displaying 1-10 of 100
Sort by:
Attacker Value
Unknown

CVE-2024-49352

Disclosure Date: February 05, 2025 (last updated February 05, 2025)
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
Attacker Value
Unknown

CVE-2023-38009

Disclosure Date: January 26, 2025 (last updated January 27, 2025)
IBM Cognos Mobile Client 1.1 iOS may be vulnerable to information disclosure through man in the middle techniques due to the lack of certificate pinning.
Attacker Value
Unknown

CVE-2024-51466

Disclosure Date: December 20, 2024 (last updated December 21, 2024)
IBM Cognos Analytics 11.2.0 through 11.2.4 FP4 and 12.0.0 through 12.0.4 is vulnerable to an Expression Language (EL) Injection vulnerability. A remote attacker could exploit this vulnerability to expose sensitive information, consume memory resources, and/or cause the server to crash when using a specially crafted EL statement.
Attacker Value
Unknown

CVE-2024-40695

Disclosure Date: December 20, 2024 (last updated December 21, 2024)
IBM Cognos Analytics 11.2.0 through 11.2.4 FP4 and 12.0.0 through 12.0.4 could be vulnerable to malicious file upload by not validating the content of the file uploaded to the web interface. Attackers can make use of this weakness and upload malicious executable files into the system, and it can be sent to victim for performing further attacks.
Attacker Value
Unknown

CVE-2021-39081

Disclosure Date: December 19, 2024 (last updated December 19, 2024)
IBM Cognos Analytics Mobile for Android 1.1.14 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
Attacker Value
Unknown

CVE-2024-45082

Disclosure Date: December 18, 2024 (last updated January 13, 2025)
IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted.
Attacker Value
Unknown

CVE-2024-41752

Disclosure Date: December 18, 2024 (last updated January 13, 2025)
IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
Attacker Value
Unknown

CVE-2024-25042

Disclosure Date: December 18, 2024 (last updated January 13, 2025)
IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 is potentially vulnerable to Cross Site Scripting (XSS). A remote attacker could execute malicious commands due to improper validation of column headings in Cognos Explorations.
Attacker Value
Unknown

CVE-2024-40703

Disclosure Date: September 22, 2024 (last updated September 28, 2024)
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and IBM Cognos Analytics Reports for iOS 11.0.0.7 could allow a local attacker to obtain sensitive information in the form of an API key. An attacker could use this information to launch further attacks against affected applications.
Attacker Value
Unknown

CVE-2024-25053

Disclosure Date: June 28, 2024 (last updated August 02, 2024)
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, and 12.0.2 is vulnerable to improper certificate validation when using the IBM Planning Analytics Data Source Connection. This could allow an attacker to spoof a trusted entity by interfering in the communication path between IBM Planning Analytics server and IBM Cognos Analytics server. IBM X-Force ID: 283364.