CVE-2025-1994
- EPSS 0.02%
- Published 26.08.2025 16:49:03
- Last modified 02.09.2025 18:07:05
IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a local user to execute arbitrary code on the system due to the use of unsafe use of the BinaryFormatter function.
CVE-2025-2697
- EPSS 0.04%
- Published 26.08.2025 16:47:25
- Last modified 02.09.2025 18:06:52
IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability...
CVE-2025-1494
- EPSS 0.04%
- Published 26.08.2025 16:45:35
- Last modified 02.09.2025 18:07:42
IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's c...
CVE-2024-31899
- EPSS 0.04%
- Published 26.09.2024 14:15:08
- Last modified 07.01.2025 20:02:40
IBM Cognos Command Center 10.2.4.1 and 10.2.5 could disclose highly sensitive user information to an authenticated user with physical access to the device.
CVE-2023-50324
- EPSS 0.06%
- Published 01.03.2024 02:15:07
- Last modified 23.04.2025 19:39:00
IBM Cognos Command Center 10.2.4.1 and 10.2.5 exposes details the X-AspNet-Version Response Header that could allow an attacker to obtain information of the application environment to conduct further attacks. IBM X-Force ID: 275038.
CVE-2022-38707
- EPSS 0.02%
- Published 05.05.2023 14:15:09
- Last modified 21.11.2024 07:16:58
IBM Cognos Command Center 10.2.4.1 could allow a local attacker to obtain sensitive information due to insufficient session expiration. IBM X-Force ID: 234179.
CVE-2013-4000
- EPSS 0.1%
- Published 14.12.2013 22:55:02
- Last modified 11.04.2025 00:51:21
Multiple cross-site request forgery (CSRF) vulnerabilities in IBM Cognos Command Center before 10.2 allow remote attackers to hijack the authentication of administrators for requests that (1) start or (2) stop services.
CVE-2013-4001
- EPSS 0.19%
- Published 14.12.2013 22:55:02
- Last modified 11.04.2025 00:51:21
Session fixation vulnerability in IBM Cognos Command Center before 10.2 allows remote attackers to hijack web sessions via an authorization cookie.