CVE-2023-43051
- EPSS 0.22%
- Published 26.02.2024 16:27:46
- Last modified 17.12.2024 18:08:08
IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclo...
CVE-2022-34357
- EPSS 0.07%
- Published 26.02.2024 16:27:45
- Last modified 17.12.2024 16:49:34
IBM Cognos Analytics Mobile Server 11.1.7, 11.2.4, and 12.0.0 is vulnerable to Denial of Service due to due to weak or absence of rate limiting. By making unlimited http requests, it is possible for a single user to exhaust server resources over a pe...
CVE-2023-35011
- EPSS 0.05%
- Published 16.08.2023 23:15:10
- Last modified 21.11.2024 08:07:49
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating ot...
CVE-2023-35009
- EPSS 0.06%
- Published 16.08.2023 23:15:09
- Last modified 21.11.2024 08:07:49
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a remote attacker to obtain system information without authentication which could be used in reconnaissance to gather information that could be used for future attacks. IBM X-Force ID: 257...
CVE-2023-25929
- EPSS 0.16%
- Published 22.07.2023 02:15:47
- Last modified 21.11.2024 07:50:26
IBM Cognos Analytics 11.1 and 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a...
CVE-2023-28530
- EPSS 0.1%
- Published 22.07.2023 02:15:47
- Last modified 21.11.2024 07:55:17
IBM Cognos Analytics 11.1 and 11.2 is vulnerable to stored cross-site scripting, caused by improper validation of SVG Files in Custom Visualizations. A remote attacker could exploit this vulnerability to execute scripts in a victim's Web browser with...
CVE-2021-39036
- EPSS 0.15%
- Published 12.05.2023 01:15:09
- Last modified 21.11.2024 06:18:28
IBM Cognos Analytics 11.1 and 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a...
CVE-2022-38708
- EPSS 0.07%
- Published 19.12.2022 21:15:10
- Last modified 21.11.2024 07:16:58
IBM Cognos Analytics 11.1.7 11.2.0, and 11.2.1 could be vulnerable to a Server-Side Request Forgery Attack (SSRF) attack by constructing URLs from user-controlled data. This could enable attackers to make arbitrary requests to the internal network o...
CVE-2022-39160
- EPSS 0.11%
- Published 19.12.2022 21:15:10
- Last modified 21.11.2024 07:17:41
IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials discl...
CVE-2022-43883
- EPSS 0.07%
- Published 19.12.2022 21:15:10
- Last modified 21.11.2024 07:27:19
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could be vulnerable to a Log Injection attack by constructing URLs from user-controlled data. This could enable attackers to make arbitrary requests to the internal network or to the local file system....