
CVE-2024-45082 – IBM Cognos Analytics HTTP open redirection
https://notcve.org/view.php?id=CVE-2024-45082
18 Dec 2024 — IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 could allow a remote attacker to conduct phishing attacks, using an ... • https://www.ibm.com/support/pages/node/7177223 • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •

CVE-2024-41752 – IBM Cognos Analytics HTML injection
https://notcve.org/view.php?id=CVE-2024-41752
18 Dec 2024 — IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security conte... • https://www.ibm.com/support/pages/node/7177223 • CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) •

CVE-2024-40703 – IBM Cognos Analytics information disclosure
https://notcve.org/view.php?id=CVE-2024-40703
22 Sep 2024 — IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and IBM Cognos Analytics Reports for iOS 11.0.0.7 could allow a local attacker to obtain sensitive information in the form of an API key. An attacker could use this information to launch further attacks against affected applications. • https://www.ibm.com/support/pages/node/7160700 • CWE-522: Insufficiently Protected Credentials •

CVE-2024-25041 – IBM Cognos Analytics cross-site scripting
https://notcve.org/view.php?id=CVE-2024-25041
28 Jun 2024 — IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, and 12.0.2 is potentially vulnerable to cross site scripting (XSS). A remote attacker could execute malicious commands due to improper validation of column headings in Cognos Assistant. IBM X-Force ID: 282780. IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1 y 12.0.2 es potencialmente vulnerable a cross site scripting (XSS). Un atacante remoto podría ejecutar comandos maliciosos debido a una validación in... • https://exchange.xforce.ibmcloud.com/vulnerabilities/282780 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2024-25053 – IBM Cognos Analytics improper certificate validation
https://notcve.org/view.php?id=CVE-2024-25053
28 Jun 2024 — IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, and 12.0.2 is vulnerable to improper certificate validation when using the IBM Planning Analytics Data Source Connection. This could allow an attacker to spoof a trusted entity by interfering in the communication path between IBM Planning Analytics server and IBM Cognos Analytics server. IBM X-Force ID: 283364. IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1 y 12.0.2 es vulnerable a una validación de cer... • https://exchange.xforce.ibmcloud.com/vulnerabilities/283364 • CWE-295: Improper Certificate Validation •

CVE-2024-25047 – IBM Cognos Analytics log injection
https://notcve.org/view.php?id=CVE-2024-25047
02 May 2024 — IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.2 is vulnerable to injection attacks in application logging by not sanitizing user provided data. This could lead to further attacks against the system. IBM X-Force ID: 282956. IBM Cognos Analytics 11.2.0 a 11.2.4 y 12.0.0 a 12.0.2 es vulnerable a ataques de inyección en el registro de aplicaciones al no sanitizar los datos proporcionados por el usuario. Esto podría dar lugar a nuevos ataques contra el sistema. • https://exchange.xforce.ibmcloud.com/vulnerabilities/282956 • CWE-117: Improper Output Neutralization for Logs •

CVE-2023-30996 – IBM Cognos Analytics cross-origin resource sharing
https://notcve.org/view.php?id=CVE-2023-30996
24 Feb 2024 — IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 could be vulnerable to information leakage due to unverified sources in messages sent between Windows objects of different origins. IBM X-Force ID: 254290. IBM Cognos Analytics 11.1.7, 11.2.4 y 12.0.0 podrían ser vulnerables a la fuga de información debido a fuentes no verificadas en mensajes enviados entre objetos de Windows de diferentes orígenes. ID de IBM X-Force: 254290. • https://exchange.xforce.ibmcloud.com/vulnerabilities/254290 • CWE-346: Origin Validation Error •

CVE-2023-32344 – IBM Cognos Analytics cross-site request forgery
https://notcve.org/view.php?id=CVE-2023-32344
24 Feb 2024 — IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 is vulnerable to form action hijacking where it is possible to modify the form action to reference an arbitrary path. IBM X-Force ID: 255898. IBM Cognos Analytics 11.1.7, 11.2.4 y 12.0.0 es vulnerable al secuestro de acciones de formulario, donde es posible modificar la acción de formulario para hacer referencia a una ruta arbitraria. ID de IBM X-Force: 255898. • https://exchange.xforce.ibmcloud.com/vulnerabilities/255898 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2023-38359 – IBM Cognos Analytics cross-site scripting
https://notcve.org/view.php?id=CVE-2023-38359
24 Feb 2024 — IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 260744. IBM Cognos Analytics 11.1.7, 11.2.4 y 12.0.0 es vulnerable a cross-site scripting. Esta vulnerabilidad permite a los usuarios incrustar código JavaScript arbitrario en la interfaz de usuario web, alterando a... • https://exchange.xforce.ibmcloud.com/vulnerabilities/260744 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2023-35011 – IBM Cognos Analytics server-side request forgey
https://notcve.org/view.php?id=CVE-2023-35011
16 Aug 2023 — IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 257705. • https://exchange.xforce.ibmcloud.com/vulnerabilities/257705 • CWE-918: Server-Side Request Forgery (SSRF) •