
CVE-2022-36773
https://notcve.org/view.php?id=CVE-2022-36773
01 Sep 2022 — IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 233571. IBM Cognos Analytics versiones 11.1.7, 11.2.0 y 11.2.1 es vulnerable a un ataque de tipo XML External Entity Injection (XXE) cuando son procesados datos XML. Un atacante remoto podría aprovechar esta vulnerabilidad para exponer información... • https://exchange.xforce.ibmcloud.com/vulnerabilities/233571 • CWE-611: Improper Restriction of XML External Entity Reference •

CVE-2022-30614
https://notcve.org/view.php?id=CVE-2022-30614
01 Sep 2022 — IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to a denial of service via email flooding caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume all available CPU resources. IBM X-Force ID: 227591. IBM Cognos Analytics versiones 11.1.7, 11.2.0 y 11.2.1, es vulnerable a una denegación de servicio por inundación de correo electrónico causada por el envío de una petición especialmente diseñada. Un atacante remoto podría apr... • https://exchange.xforce.ibmcloud.com/vulnerabilities/227591 •

CVE-2021-39045
https://notcve.org/view.php?id=CVE-2021-39045
01 Sep 2022 — IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a local attacker to obtain information due to the autocomplete feature on password input fields. IBM X-Force ID: 214345. IBM Cognos Analytics versiones 11.1.7, 11.2.0 y 11.2.1, podrían permitir a un atacante local obtener información debido a la funcionalidad autocomplete en los campos de entrada de contraseñas. IBM X-Force ID: 214345 • https://exchange.xforce.ibmcloud.com/vulnerabilities/214345 • CWE-522: Insufficiently Protected Credentials •

CVE-2021-39009
https://notcve.org/view.php?id=CVE-2021-39009
01 Sep 2022 — IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 stores user credentials in plain clear text which can be read by a local privileged user. IBM X-Force ID: 213554. IBM Cognos Analytics versiones 11.1.7, 11.2.0 y 11.2.1, almacena las credenciales de usuario en texto sin cifrar que puede ser leído por un usuario local privilegiado. IBM X-Force ID: 213554 • https://exchange.xforce.ibmcloud.com/vulnerabilities/213554 • CWE-312: Cleartext Storage of Sensitive Information •

CVE-2021-29823
https://notcve.org/view.php?id=CVE-2021-29823
01 Sep 2022 — IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 204465. IBM Cognos Analytics versiones 11.1.7, 11.2.0 y 11.2.1, es vulnerable a un ataque de tipo cross-site request forgery, lo que podría permitir a un atacante ejecutar acciones maliciosas y no autorizadas transmitidas desde un usuario en el que el sitio web confía. IBM X-For... • https://exchange.xforce.ibmcloud.com/vulnerabilities/204465 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2021-20468
https://notcve.org/view.php?id=CVE-2021-20468
01 Sep 2022 — IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 196825. IBM Cognos Analytics versiones 11.1.7, 11.2.0 y 11.2.1, es vulnerable a un ataque de tipo cross-site request forgery, lo que podría permitir a un atacante ejecutar acciones maliciosas y no autorizadas transmitidas desde un usuario en el que el sitio web confía. IBM X-For... • https://exchange.xforce.ibmcloud.com/vulnerabilities/196825 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2020-4301
https://notcve.org/view.php?id=CVE-2020-4301
01 Sep 2022 — IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 176609. IBM Cognos Analytics versiones 11.1.7, 11.2.0 y 11.2.1, es vulnerable a un ataque de tipo cross-site request forgery, lo que podría permitir a un atacante ejecutar acciones maliciosas y no autorizadas transmitidas desde un usuario en el que el sitio web confía. IBM X-For... • https://exchange.xforce.ibmcloud.com/vulnerabilities/176609 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2021-39047
https://notcve.org/view.php?id=CVE-2021-39047
24 Jun 2022 — IBM Planning Analytics 2.0 and IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 214349. IBM Planning Analytics versión 2.0 e IBM Cognos Analytics versiones 11.2.1, 11.2.0 y 11.1.7, son vulnerables a un ataque de tipo cross-site scripting. Esta vulnerabilidad perm... • https://exchange.xforce.ibmcloud.com/vulnerabilities/214349 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2021-38945
https://notcve.org/view.php?id=CVE-2021-38945
24 Jun 2022 — IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 could allow a remote attacker to upload arbitrary files, caused by improper content validation. IBM X-Force ID: 211238. IBM Cognos Analytics versiones 11.2.1, 11.2.0 y 11.1.7, podrían permitir a un atacante remoto cargar archivos arbitrarios, causados por una incorrecta comprobación del contenido. IBM X-Force ID: 211238 • https://exchange.xforce.ibmcloud.com/vulnerabilities/211238 • CWE-434: Unrestricted Upload of File with Dangerous Type •

CVE-2021-29768
https://notcve.org/view.php?id=CVE-2021-29768
24 Jun 2022 — IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a low level user to obtain sensitive information from the details of the 'Cloud Storage' page for which they should not have access. IBM X-Force ID: 202682. IBM Cognos Analytics versiones 11.1.7, 11.2.0 y 11.2.1, podría permitir a un usuario de bajo nivel obtener información confidencial de los detalles de la página "Cloud Storage" a la que no debería tener acceso. IBM X-Force ID: 202682 • https://exchange.xforce.ibmcloud.com/vulnerabilities/202682 •