Show filters
42 Total Results
Displaying 1-10 of 42
Sort by:
Attacker Value
Unknown
CVE-2023-43051
Disclosure Date: February 26, 2024 (last updated December 18, 2024)
IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 267451.
0
Attacker Value
Unknown
CVE-2023-38359
Disclosure Date: February 26, 2024 (last updated December 18, 2024)
IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 260744.
0
Attacker Value
Unknown
CVE-2023-32344
Disclosure Date: February 26, 2024 (last updated December 18, 2024)
IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 is vulnerable to form action hijacking where it is possible to modify the form action to reference an arbitrary path. IBM X-Force ID: 255898.
0
Attacker Value
Unknown
CVE-2023-30996
Disclosure Date: February 26, 2024 (last updated December 18, 2024)
IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 could be vulnerable to information leakage due to unverified sources in messages sent between Windows objects of different origins. IBM X-Force ID: 254290.
0
Attacker Value
Unknown
CVE-2022-34357
Disclosure Date: February 26, 2024 (last updated December 18, 2024)
IBM Cognos Analytics Mobile Server 11.1.7, 11.2.4, and 12.0.0 is vulnerable to Denial of Service due to due to weak or absence of rate limiting. By making unlimited http requests, it is possible for a single user to exhaust server resources over a period of time making service unavailable for other legitimate users. IBM X-Force ID: 230510.
0
Attacker Value
Unknown
CVE-2023-35011
Disclosure Date: August 16, 2023 (last updated October 08, 2023)
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 257705.
0
Attacker Value
Unknown
CVE-2023-35009
Disclosure Date: August 16, 2023 (last updated October 08, 2023)
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a remote attacker to obtain system information without authentication which could be used in reconnaissance to gather information that could be used for future attacks. IBM X-Force ID: 257703.
0
Attacker Value
Unknown
CVE-2023-28530
Disclosure Date: July 22, 2023 (last updated October 08, 2023)
IBM Cognos Analytics 11.1 and 11.2 is vulnerable to stored cross-site scripting, caused by improper validation of SVG Files in Custom Visualizations. A remote attacker could exploit this vulnerability to execute scripts in a victim's Web browser within the security context of the hosting Web site. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials. IBM X-Force ID: 251214.
0
Attacker Value
Unknown
CVE-2023-25929
Disclosure Date: July 22, 2023 (last updated October 08, 2023)
IBM Cognos Analytics 11.1 and 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 247861.
0
Attacker Value
Unknown
CVE-2022-43887
Disclosure Date: December 19, 2022 (last updated November 08, 2023)
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could be vulnerable to sensitive information exposure by passing API keys to log files. If these keys contain sensitive information, it could lead to further attacks. IBM X-Force ID: 240450.
0