Skip to main content

Vendor/product archive

ibm / cognos_command_center CVEs

Beta · best-effort

8 CVEs tagged to ibm / cognos_command_center0 Critical, 2 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2025-2697

Published Aug 26, 2025

IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a special…

CVSS 7.4 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-1994

Published Aug 26, 2025

IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a local user to execute arbitrary code on the system due to the use of unsafe use of the BinaryFormatter function.

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-1494

Published Aug 26, 2025

IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a re…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-31899

Published Sep 26, 2024

IBM Cognos Command Center 10.2.4.1 and 10.2.5 could disclose highly sensitive user information to an authenticated user with physical access to the device.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-50324

Published Mar 1, 2024

IBM Cognos Command Center 10.2.4.1 and 10.2.5 exposes details the X-AspNet-Version Response Header that could allow an attacker to obtain information of the application environmen…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-38707

Published May 5, 2023

IBM Cognos Command Center 10.2.4.1 could allow a local attacker to obtain sensitive information due to insufficient session expiration. IBM X-Force ID: 234179.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4001

Published Dec 14, 2013

Session fixation vulnerability in IBM Cognos Command Center before 10.2 allows remote attackers to hijack web sessions via an authorization cookie.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4000

Published Dec 14, 2013

Multiple cross-site request forgery (CSRF) vulnerabilities in IBM Cognos Command Center before 10.2 allow remote attackers to hijack the authentication of administrators for reque…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1