Ibm

Cognos Analytics

110 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.18%
  • Veröffentlicht 11.06.2025 17:27:49
  • Zuletzt bearbeitet 17.06.2025 20:33:21

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus al...

  • EPSS 0.34%
  • Veröffentlicht 11.06.2025 17:26:35
  • Zuletzt bearbeitet 17.06.2025 20:33:07

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 could allow an authenticated user to cause a denial of service by sending a specially crafted request that would exhaust memory resources.

  • EPSS 0.81%
  • Veröffentlicht 28.02.2025 03:15:10
  • Zuletzt bearbeitet 17.10.2025 16:15:36

IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 is vulnerable to local file inclusion vulnerability, allowing an attacker to access sensitive files by inserting path traversal payloads inside the deficon parameter.

  • EPSS 0.58%
  • Veröffentlicht 28.02.2025 03:15:10
  • Zuletzt bearbeitet 02.07.2025 15:59:20

IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 and 12.0.0 through 12.0.4 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitra...

  • EPSS 0.47%
  • Veröffentlicht 05.02.2025 11:15:14
  • Zuletzt bearbeitet 02.07.2025 15:59:03

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to exp...

  • EPSS 0.2%
  • Veröffentlicht 26.01.2025 16:15:30
  • Zuletzt bearbeitet 18.08.2025 17:57:33

IBM Cognos Mobile Client 1.1 iOS may be vulnerable to information disclosure through man in the middle techniques due to the lack of certificate pinning.

Medienbericht
  • EPSS 0.43%
  • Veröffentlicht 20.12.2024 14:15:24
  • Zuletzt bearbeitet 02.07.2025 15:53:18

IBM Cognos Analytics 11.2.0 through 11.2.4 FP4 and 12.0.0 through 12.0.4 could be vulnerable to malicious file upload by not validating the content of the file uploaded to the web interface. Attackers can make use of this weakness and upload mal...

Medienbericht
  • EPSS 0.6%
  • Veröffentlicht 20.12.2024 14:15:24
  • Zuletzt bearbeitet 02.07.2025 15:58:56

IBM Cognos Analytics 11.2.0 through 11.2.4 FP4 and 12.0.0 through 12.0.4 is vulnerable to an Expression Language (EL) Injection vulnerability. A remote attacker could exploit this vulnerability to expose sensitive information, consume memory resou...

  • EPSS 0.27%
  • Veröffentlicht 18.12.2024 17:15:13
  • Zuletzt bearbeitet 10.01.2025 19:31:43

IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 is potentially vulnerable to Cross Site Scripting (XSS). A remote attacker could execute malicious commands due to improper validation of column headings in Cognos Explorations.

  • EPSS 0.27%
  • Veröffentlicht 18.12.2024 17:15:13
  • Zuletzt bearbeitet 10.01.2025 19:33:46

IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of ...