CVE-2023-35011
- EPSS 0.46%
- Veröffentlicht 16.08.2023 23:15:10
- Zuletzt bearbeitet 21.11.2024 08:07:49
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating ot...
CVE-2023-35009
- EPSS 1.01%
- Veröffentlicht 16.08.2023 23:15:09
- Zuletzt bearbeitet 21.11.2024 08:07:49
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a remote attacker to obtain system information without authentication which could be used in reconnaissance to gather information that could be used for future attacks. IBM X-Force ID: 257...
CVE-2023-25929
- EPSS 0.49%
- Veröffentlicht 22.07.2023 02:15:47
- Zuletzt bearbeitet 21.11.2024 07:50:26
IBM Cognos Analytics 11.1 and 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a...
CVE-2023-28530
- EPSS 0.68%
- Veröffentlicht 22.07.2023 02:15:47
- Zuletzt bearbeitet 21.11.2024 07:55:17
IBM Cognos Analytics 11.1 and 11.2 is vulnerable to stored cross-site scripting, caused by improper validation of SVG Files in Custom Visualizations. A remote attacker could exploit this vulnerability to execute scripts in a victim's Web browser with...
CVE-2021-39036
- EPSS 0.53%
- Veröffentlicht 12.05.2023 01:15:09
- Zuletzt bearbeitet 21.11.2024 06:18:28
IBM Cognos Analytics 11.1 and 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a...
CVE-2022-38708
- EPSS 0.43%
- Veröffentlicht 19.12.2022 21:15:10
- Zuletzt bearbeitet 21.11.2024 07:16:58
IBM Cognos Analytics 11.1.7 11.2.0, and 11.2.1 could be vulnerable to a Server-Side Request Forgery Attack (SSRF) attack by constructing URLs from user-controlled data. This could enable attackers to make arbitrary requests to the internal network o...
CVE-2022-39160
- EPSS 0.39%
- Veröffentlicht 19.12.2022 21:15:10
- Zuletzt bearbeitet 21.11.2024 07:17:41
IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials discl...
CVE-2022-43883
- EPSS 0.59%
- Veröffentlicht 19.12.2022 21:15:10
- Zuletzt bearbeitet 21.11.2024 07:27:19
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could be vulnerable to a Log Injection attack by constructing URLs from user-controlled data. This could enable attackers to make arbitrary requests to the internal network or to the local file system....
CVE-2022-43887
- EPSS 0.53%
- Veröffentlicht 19.12.2022 21:15:10
- Zuletzt bearbeitet 21.11.2024 07:27:19
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could be vulnerable to sensitive information exposure by passing API keys to log files. If these keys contain sensitive information, it could lead to further attacks. IBM X-Force ID: 240450.
CVE-2022-34339
- EPSS 0.41%
- Veröffentlicht 03.11.2022 20:15:28
- Zuletzt bearbeitet 02.05.2025 21:15:17
"IBM Cognos Analytics 11.2.1, 11.2.0, 11.1.7 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 229963."