Page 5 of 40 results (0.020 seconds)

CVSS: 5.4EPSS: 0%CPEs: 4EXPL: 0

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 211240. IBM Cognos Analytics 11.1.7, 11.2.0 y 11.1.7, es vulnerable a un ataque de tipo cross-site scripting. Esta vulnerabilidad permite a usuarios insertar código JavaScript arbitrario en la Interfaz de Usuario Web, alterando así la funcionalidad prevista y conllevando potencialmente a una divulgación de credenciales dentro de una sesión confiable. • https://exchange.xforce.ibmcloud.com/vulnerabilities/211240 https://security.netapp.com/advisory/ntap-20220602-0003 https://www.ibm.com/support/pages/node/6570957 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 4.3EPSS: 0%CPEs: 4EXPL: 0

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 could allow an authenticated user to view report pages that they should not have access to. IBM X-Force ID: 209697. IBM Cognos Analytics versiones 11.1.7, 11.2.0 y 11.1.7, podría permitir a un usuario autenticado visualizar páginas de informes a las que no debería tener acceso. IBM X-Force ID: 209697 • https://exchange.xforce.ibmcloud.com/vulnerabilities/209697 https://security.netapp.com/advisory/ntap-20220602-0003 https://www.ibm.com/support/pages/node/6570957 •

CVSS: 6.5EPSS: 0%CPEs: 4EXPL: 0

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 could allow a remote attacker to obtain credentials from a user's browser via incorrect autocomplete settings. IBM X-Force ID: 209693. IBM Cognos Analytics versiones 11.1.7, 11.2.0 y 11.1.7, podrían permitir a un atacante remoto obtener credenciales del navegador de un usuario por medio de una configuración incorrecta de autocompletar. IBM X-Force ID: 209693 • https://exchange.xforce.ibmcloud.com/vulnerabilities/209693 https://security.netapp.com/advisory/ntap-20220602-0003 https://www.ibm.com/support/pages/node/6570957 •

CVSS: 5.4EPSS: 0%CPEs: 4EXPL: 0

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials. IBM X-Force ID: 209691. IBM Cognos Analytics versiones 11.1.7, 11.2.0 y 11.1.7, es vulnerable a un ataque de tipo cross-site scripting, causadas por una comprobación inapropiada de entrada suministrada por el usuario. • https://exchange.xforce.ibmcloud.com/vulnerabilities/209691 https://security.netapp.com/advisory/ntap-20220602-0003 https://www.ibm.com/support/pages/node/6570957 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 8.8EPSS: 0%CPEs: 4EXPL: 0

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 209399. IBM Cognos Analytics versiones 11.1.7, 11.2.0 y 11.1.7, es vulnerable a un ataque de tipo cross-site request forgery, lo que podría permitir a un atacante ejecutar acciones maliciosas y no autorizadas transmitidas desde un usuario en el que el sitio web confía. IBM X-Force ID: 209399 • https://exchange.xforce.ibmcloud.com/vulnerabilities/209399 https://security.netapp.com/advisory/ntap-20220602-0003 https://www.ibm.com/support/pages/node/6570957 • CWE-352: Cross-Site Request Forgery (CSRF) •