CVE-2024-25042
- EPSS 0.05%
- Published 18.12.2024 17:15:13
- Last modified 10.01.2025 19:31:43
IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 is potentially vulnerable to Cross Site Scripting (XSS). A remote attacker could execute malicious commands due to improper validation of column headings in Cognos Explorations.
CVE-2024-41752
- EPSS 0.04%
- Published 18.12.2024 17:15:13
- Last modified 10.01.2025 19:33:46
IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of ...
CVE-2024-45082
- EPSS 0.02%
- Published 18.12.2024 17:15:13
- Last modified 10.01.2025 19:34:56
IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exp...
CVE-2024-40703
- EPSS 0.02%
- Published 22.09.2024 13:15:10
- Last modified 27.09.2024 16:49:46
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and IBM Cognos Analytics Reports for iOS 11.0.0.7 could allow a local attacker to obtain sensitive information in the form of an API key. An attacker could ...
CVE-2024-25041
- EPSS 0.04%
- Published 28.06.2024 19:15:04
- Last modified 21.11.2024 09:00:09
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, and 12.0.2 is potentially vulnerable to cross site scripting (XSS). A remote attacker could execute malicious commands due to improper validation of column headings in Cogno...
CVE-2024-25053
- EPSS 0.08%
- Published 28.06.2024 19:15:04
- Last modified 21.11.2024 09:00:10
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, and 12.0.2 is vulnerable to improper certificate validation when using the IBM Planning Analytics Data Source Connection. This could allow an attacker to spoof a trusted ent...
CVE-2024-25047
- EPSS 0.06%
- Published 02.05.2024 21:16:11
- Last modified 02.07.2025 15:41:45
IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.2 is vulnerable to injection attacks in application logging by not sanitizing user provided data. This could lead to further attacks against the system. IBM X-Force ID: 282956.
CVE-2023-30996
- EPSS 0.07%
- Published 26.02.2024 16:27:46
- Last modified 17.12.2024 19:32:35
IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 could be vulnerable to information leakage due to unverified sources in messages sent between Windows objects of different origins. IBM X-Force ID: 254290.
CVE-2023-32344
- EPSS 0.03%
- Published 26.02.2024 16:27:46
- Last modified 17.12.2024 18:55:38
IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 is vulnerable to form action hijacking where it is possible to modify the form action to reference an arbitrary path. IBM X-Force ID: 255898.
CVE-2023-38359
- EPSS 0.09%
- Published 26.02.2024 16:27:46
- Last modified 17.12.2024 18:55:23
IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclo...