Skip to main content

Vendor/product archive

ibm / cognos_analytics CVEs

Beta · best-effort

104 CVEs tagged to ibm / cognos_analytics4 Critical, 21 High, 77 Medium, 2 Low, 0 Unrated.

CVE-2025-3633

Published May 27, 2026

IBM Cognos Analytics 11.2.0, 11.2.4, 12.0, and 12.1.0 and IBM Cognos Transformer 11.2.4, 12.0, and 12.1.0 are vulnerable to cross-site scripting (XSS). This vulnerability allows a…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-36126

Published May 26, 2026

IBM Cognos Analytics 11.2.0, 12.0, and 12.1.0 and IBM Cognos Transformer 12.0, 11.2.4, and 12.1.0 is vulnerable to stored cross-site scripting (XSS) in Cognos Adminstration. This…

CVSS 6.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-52900

Published Jun 28, 2025

IBM Cognos Analytics 11.2.0 through 12.2.4 Fix Pack 5 and 12.0.0 through 12.0.4 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embe…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-25032

Published Jun 11, 2025

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 could allow an authenticated user to cause a denial of service by sending a…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-0923

Published Jun 11, 2025

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 stores source code on the web server that could aid in further attacks agai…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-0917

Published Jun 11, 2025

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 is vulnerable to stored cross-site scripting. This vulnerability allows a p…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-0823

Published Feb 28, 2025

IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 and 12.0.0 through 12.0.4 could allow a remote attacker to traverse directories on the system. An attacker could send a specially cr…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-56340

Published Feb 28, 2025

IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 is vulnerable to local file inclusion vulnerability, allowing an attacker to access sensitive files by inserting path traversal payl…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-49352

Published Feb 5, 2025

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 is vulnerable to an XML External Entity Injection (XXE) attack when process…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-51466

Published Dec 20, 2024

IBM Cognos Analytics 11.2.0 through 11.2.4 FP4 and 12.0.0 through 12.0.4 is vulnerable to an Expression Language (EL) Injection vulnerability. A remote attacker could exploit t…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-40695

Published Dec 20, 2024

IBM Cognos Analytics 11.2.0 through 11.2.4 FP4 and 12.0.0 through 12.0.4 could be vulnerable to malicious file upload by not validating the content of the file uploaded to th…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2024-45082

Published Dec 18, 2024

IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a vi…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-41752

Published Dec 18, 2024

IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-25042

Published Dec 18, 2024

IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 is potentially vulnerable to Cross Site Scripting (XSS). A remote attacker could execute malicious command…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-25053

Published Jun 28, 2024

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, and 12.0.2 is vulnerable to improper certificate validation when using the IBM Planning Analytics Data…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-25041

Published Jun 28, 2024

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, and 12.0.2 is potentially vulnerable to cross site scripting (XSS). A remote attacker could execute ma…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-35011

Published Aug 16, 2023

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from th…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 104 CVEsPage 1 of 5