CVE-2021-38905
https://notcve.org/view.php?id=CVE-2021-38905
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 could allow an authenticated user to view report pages that they should not have access to. IBM X-Force ID: 209697. IBM Cognos Analytics versiones 11.1.7, 11.2.0 y 11.1.7, podría permitir a un usuario autenticado visualizar páginas de informes a las que no debería tener acceso. IBM X-Force ID: 209697 • https://exchange.xforce.ibmcloud.com/vulnerabilities/209697 https://security.netapp.com/advisory/ntap-20220602-0003 https://www.ibm.com/support/pages/node/6570957 •
CVE-2021-38904
https://notcve.org/view.php?id=CVE-2021-38904
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 could allow a remote attacker to obtain credentials from a user's browser via incorrect autocomplete settings. IBM X-Force ID: 209693. IBM Cognos Analytics versiones 11.1.7, 11.2.0 y 11.1.7, podrían permitir a un atacante remoto obtener credenciales del navegador de un usuario por medio de una configuración incorrecta de autocompletar. IBM X-Force ID: 209693 • https://exchange.xforce.ibmcloud.com/vulnerabilities/209693 https://security.netapp.com/advisory/ntap-20220602-0003 https://www.ibm.com/support/pages/node/6570957 •
CVE-2021-38903
https://notcve.org/view.php?id=CVE-2021-38903
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials. IBM X-Force ID: 209691. IBM Cognos Analytics versiones 11.1.7, 11.2.0 y 11.1.7, es vulnerable a un ataque de tipo cross-site scripting, causadas por una comprobación inapropiada de entrada suministrada por el usuario. • https://exchange.xforce.ibmcloud.com/vulnerabilities/209691 https://security.netapp.com/advisory/ntap-20220602-0003 https://www.ibm.com/support/pages/node/6570957 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2021-38886
https://notcve.org/view.php?id=CVE-2021-38886
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 209399. IBM Cognos Analytics versiones 11.1.7, 11.2.0 y 11.1.7, es vulnerable a un ataque de tipo cross-site request forgery, lo que podría permitir a un atacante ejecutar acciones maliciosas y no autorizadas transmitidas desde un usuario en el que el sitio web confía. IBM X-Force ID: 209399 • https://exchange.xforce.ibmcloud.com/vulnerabilities/209399 https://security.netapp.com/advisory/ntap-20220602-0003 https://www.ibm.com/support/pages/node/6570957 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2021-29824
https://notcve.org/view.php?id=CVE-2021-29824
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to priviledge escalation where a lower level user could have read access to to the 'Data Connections' page to which they don't have access. IBM X-Force ID: 204468. IBM Cognos Analytics versiones 11.1.7, 11.2.0 y 11.1.7, es vulnerable a una escalada de privilegios en la que un usuario de nivel inferior podría tener acceso de lectura a la página "Data Connections" a la que no presenta acceso. IBM X-Force ID: 204468 • https://exchange.xforce.ibmcloud.com/vulnerabilities/204468 https://security.netapp.com/advisory/ntap-20220602-0003 https://www.ibm.com/support/pages/node/6570957 •