CVE-2024-25042
- EPSS 0.05%
- Veröffentlicht 18.12.2024 17:15:13
- Zuletzt bearbeitet 10.01.2025 19:31:43
IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 is potentially vulnerable to Cross Site Scripting (XSS). A remote attacker could execute malicious commands due to improper validation of column headings in Cognos Explorations.
CVE-2024-41752
- EPSS 0.04%
- Veröffentlicht 18.12.2024 17:15:13
- Zuletzt bearbeitet 10.01.2025 19:33:46
IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of ...
CVE-2024-45082
- EPSS 0.02%
- Veröffentlicht 18.12.2024 17:15:13
- Zuletzt bearbeitet 10.01.2025 19:34:56
IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exp...
CVE-2024-40703
- EPSS 0.02%
- Veröffentlicht 22.09.2024 13:15:10
- Zuletzt bearbeitet 27.09.2024 16:49:46
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and IBM Cognos Analytics Reports for iOS 11.0.0.7 could allow a local attacker to obtain sensitive information in the form of an API key. An attacker could ...
CVE-2024-25041
- EPSS 0.04%
- Veröffentlicht 28.06.2024 19:15:04
- Zuletzt bearbeitet 21.11.2024 09:00:09
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, and 12.0.2 is potentially vulnerable to cross site scripting (XSS). A remote attacker could execute malicious commands due to improper validation of column headings in Cogno...
CVE-2024-25053
- EPSS 0.08%
- Veröffentlicht 28.06.2024 19:15:04
- Zuletzt bearbeitet 21.11.2024 09:00:10
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, and 12.0.2 is vulnerable to improper certificate validation when using the IBM Planning Analytics Data Source Connection. This could allow an attacker to spoof a trusted ent...
CVE-2024-25047
- EPSS 0.06%
- Veröffentlicht 02.05.2024 21:16:11
- Zuletzt bearbeitet 02.07.2025 15:41:45
IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.2 is vulnerable to injection attacks in application logging by not sanitizing user provided data. This could lead to further attacks against the system. IBM X-Force ID: 282956.
CVE-2023-30996
- EPSS 0.07%
- Veröffentlicht 26.02.2024 16:27:46
- Zuletzt bearbeitet 17.12.2024 19:32:35
IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 could be vulnerable to information leakage due to unverified sources in messages sent between Windows objects of different origins. IBM X-Force ID: 254290.
CVE-2023-32344
- EPSS 0.03%
- Veröffentlicht 26.02.2024 16:27:46
- Zuletzt bearbeitet 17.12.2024 18:55:38
IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 is vulnerable to form action hijacking where it is possible to modify the form action to reference an arbitrary path. IBM X-Force ID: 255898.
CVE-2023-38359
- EPSS 0.09%
- Veröffentlicht 26.02.2024 16:27:46
- Zuletzt bearbeitet 17.12.2024 18:55:23
IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclo...