Ibm

Cognos Analytics

102 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.22%
  • Veröffentlicht 26.02.2024 16:27:46
  • Zuletzt bearbeitet 17.12.2024 18:08:08

IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclo...

  • EPSS 0.07%
  • Veröffentlicht 26.02.2024 16:27:45
  • Zuletzt bearbeitet 17.12.2024 16:49:34

IBM Cognos Analytics Mobile Server 11.1.7, 11.2.4, and 12.0.0 is vulnerable to Denial of Service due to due to weak or absence of rate limiting. By making unlimited http requests, it is possible for a single user to exhaust server resources over a pe...

  • EPSS 0.05%
  • Veröffentlicht 16.08.2023 23:15:10
  • Zuletzt bearbeitet 21.11.2024 08:07:49

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating ot...

  • EPSS 0.06%
  • Veröffentlicht 16.08.2023 23:15:09
  • Zuletzt bearbeitet 21.11.2024 08:07:49

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a remote attacker to obtain system information without authentication which could be used in reconnaissance to gather information that could be used for future attacks. IBM X-Force ID: 257...

  • EPSS 0.16%
  • Veröffentlicht 22.07.2023 02:15:47
  • Zuletzt bearbeitet 21.11.2024 07:50:26

IBM Cognos Analytics 11.1 and 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a...

  • EPSS 0.1%
  • Veröffentlicht 22.07.2023 02:15:47
  • Zuletzt bearbeitet 21.11.2024 07:55:17

IBM Cognos Analytics 11.1 and 11.2 is vulnerable to stored cross-site scripting, caused by improper validation of SVG Files in Custom Visualizations. A remote attacker could exploit this vulnerability to execute scripts in a victim's Web browser with...

  • EPSS 0.15%
  • Veröffentlicht 12.05.2023 01:15:09
  • Zuletzt bearbeitet 21.11.2024 06:18:28

IBM Cognos Analytics 11.1 and 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a...

  • EPSS 0.07%
  • Veröffentlicht 19.12.2022 21:15:10
  • Zuletzt bearbeitet 21.11.2024 07:16:58

IBM Cognos Analytics 11.1.7 11.2.0, and 11.2.1 could be vulnerable to a Server-Side Request Forgery Attack (SSRF) attack by constructing URLs from user-controlled data. This could enable attackers to make arbitrary requests to the internal network o...

  • EPSS 0.11%
  • Veröffentlicht 19.12.2022 21:15:10
  • Zuletzt bearbeitet 21.11.2024 07:17:41

IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials discl...

  • EPSS 0.07%
  • Veröffentlicht 19.12.2022 21:15:10
  • Zuletzt bearbeitet 21.11.2024 07:27:19

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could be vulnerable to a Log Injection attack by constructing URLs from user-controlled data. This could enable attackers to make arbitrary requests to the internal network or to the local file system....