VendorsIBMcognos_analyticsall versions
Vulnerabilities

IBM Cognos Analytics

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

105CVEs
CVE-2020-4561
IBM Cognos Analytics 11.0 and 11.1 DQM API allows submitting of all control requests in unauthenticated sessions. This allows a remote attacker who can access a valid CA endpoint to read and write files to the Cognos Analytics system. IBM X-Force ID: 183903.
Published 2021-05-31 · Modified
10.0EPSS 0.029
CVE-2021-38945
IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 could allow a remote attacker to upload arbitrary files, caused by improper content validation. IBM X-Force ID: 211238.
Published 2022-06-24 · Modified
9.8EPSS 0.017
CVE-2020-4302
IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to execute arbitrary code on the system, caused by a CSV injection. By persuading a victim to open a specially-crafted excel file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 176610.
Published 2020-10-12 · Modified
9.3EPSS 0.017
CVE-2019-4178
IBM Cognos Analytics 11 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request to write or view arbitrary files on the system. IBM X-Force ID: 158919.
Published 2019-04-15 · Modified
9.1EPSS 0.031
CVE-2020-4377
IBM Cognos Anaytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 179156.
Published 2020-08-03 · Modified
9.1EPSS 0.021
CVE-2022-38708
IBM Cognos Analytics server-side request forgery
Published 2022-12-19 · Modified
9.1EPSS 0.004
CVE-2024-51466
IBM Cognos Analytics expression language injection
Published 2024-12-20 · Analyzed
9.0EPSS 0.006
CVE-2020-4520
IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to inject malicious HTML code that when viewed by the authenticated victim would execute the code. IBM X-Force ID: 182395.
Published 2021-05-31 · Modified
8.8EPSS 0.027
CVE-2021-29679
IBM Cognos Analytics 11.1.7 and 11.2.0 could allow an authenticated user to execute code remotely due to incorrectly neutralizaing user-contrlled input that could be interpreted a a server-side include (SSI) directive. IBM X-Force ID: 199915.
Published 2021-10-15 · Modified
8.8EPSS 0.020
CVE-2018-1721
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or cause the web server to make HTTP requests to arbitrary domains. IBM X-Force ID: 147369.
Published 2019-11-09 · Modified
8.8EPSS 0.018
CVE-2021-29745
IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to priviledge escalation where a lower evel user could have access to the 'New Job' page to which they should not have access to. IBM X-Force ID: 201695.
Published 2021-10-15 · Modified
8.8EPSS 0.010
CVE-2021-29756
IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site request forgery (CSRF) in the My Inbox page which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 202167.
Published 2021-12-03 · Modified
8.8EPSS 0.006
CVE-2021-38886
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 209399.
Published 2022-04-22 · Modified
8.8EPSS 0.006
CVE-2024-25047
IBM Cognos Analytics log injection
Published 2024-05-02 · Analyzed
8.6EPSS 0.006
CVE-2020-4300
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 176607.
Published 2021-05-31 · Modified
8.2EPSS 0.040
CVE-2020-4388
IBM Cognos Analytics 11.0 and 11.1 could be vulnerable to a denial of service attack by failing to catch exceptions in a servlet also exposing debug information could also be used in future attacks. IBM X-Force ID: 179270.
Published 2020-10-12 · Modified
8.2EPSS 0.013
CVE-2025-3633
IBM Cognos Analytics is affected by multiple security vulnerabilities
Published 2026-05-27 · Analyzed
8.2EPSS 0.003
CVE-2022-36773
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 233571.
Published 2022-09-01 · Modified
8.1EPSS 0.019
CVE-2024-40695
IBM Cognos Analytics file upload
Published 2024-12-20 · Analyzed
8.0EPSS 0.004
CVE-2019-4183
IBM Cognos Analytics 11.0, and 11.1 is vulnerable to a denial of service attack that could allow a remote user to send specially crafted requests that would consume all available CPU and memory resources. IBM X-Force ID: 158973.
Published 2019-09-17 · Modified
7.8EPSS 0.035
CVE-2017-1779
IBM Cognos Analytics 11.0 could store cached credentials locally that could be obtained by a local user. IBM X-Force ID: 136824.
Published 2018-01-29 · Modified
7.8EPSS 0.004
CVE-2025-36126
IBM Cognos Analytics is affected by Cross-site scripting.
Published 2026-05-26 · Analyzed
7.6EPSS 0.002
CVE-2019-4724
IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain credentials from a user's browser via incorrect autocomplete settings in New Content Backup page. IBM X-Force ID: 172130.
Published 2021-05-31 · Modified
7.5EPSS 0.024
CVE-2019-4723
IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain credentials from a user's browser via incorrect autocomplete settings in New Data Server Connection page. IBM X-Force ID: 172129.
Published 2021-05-31 · Modified
7.5EPSS 0.024
CVE-2022-30614
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to a denial of service via email flooding caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume all available CPU resources. IBM X-Force ID: 227591.
Published 2022-09-01 · Modified
7.5EPSS 0.017
CVE-2021-20470
IBM Cognos Analytics 11.1.7 and 11.2.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 196339.
Published 2021-12-03 · Modified
7.5EPSS 0.014
CVE-2022-43883
IBM Cognos Analytics data manipulation
Published 2022-12-19 · Modified
7.5EPSS 0.006
CVE-2025-25032
IBM Cognos Analytics denial of service
Published 2025-06-11 · Analyzed
7.5EPSS 0.004
CVE-2019-4730
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 172533.
Published 2021-05-31 · Modified
7.1EPSS 0.020
CVE-2024-49352
IBM Cognos Anaytics XML external entity injection
Published 2025-02-05 · Analyzed
7.1EPSS 0.005
CVE-2024-45082
IBM Cognos Analytics HTTP open redirection
Published 2024-12-18 · Analyzed
6.8EPSS 0.002
CVE-2021-38904
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 could allow a remote attacker to obtain credentials from a user's browser via incorrect autocomplete settings. IBM X-Force ID: 209693.
Published 2022-04-22 · Modified
6.5EPSS 0.018
CVE-2019-4343
IBM Cognos Analytics 11.0 and 11.1 allows overly permissive cross-origin resource sharing which could allow an attacker to transfer private information. An attacker could exploit this vulnerability to access content that should be restricted. IBM X-Force ID: 161422.
Published 2019-12-30 · Modified
6.5EPSS 0.015
CVE-2021-20464
IBM Cognos Analytics PowerPlay (IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7) could be vulnerable to an XML Bomb attack by a malicious authenticated user. IBM X-Force ID: 196813.
Published 2022-04-22 · Modified
6.5EPSS 0.014
CVE-2022-34357
IBM Cognos Analytics Mobile Server denial of service
Published 2024-02-24 · Analyzed
6.5EPSS 0.012
CVE-2019-4471
IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain sensitive information, caused by the failure to set the secure flag for a sensitive cookie in an HTTPS session. A remote attacker could exploit this vulnerability to obtain sensitive information. IBM X-Force ID: 163780.
Published 2021-05-31 · Modified
6.5EPSS 0.010
CVE-2021-29768
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a low level user to obtain sensitive information from the details of the 'Cloud Storage' page for which they should not have access. IBM X-Force ID: 202682.
Published 2022-06-24 · Modified
6.5EPSS 0.010
CVE-2021-20461
IBM Cognos Analytics 10.0 and 11.1 is susceptible to a weakness in the implementation of the System Appearance configuration setting. An attacker could potentially bypass business logic to modify the appearance and behavior of the application. IBM X-Force ID: 196770.
Published 2021-06-30 · Modified
6.5EPSS 0.010
CVE-2021-29716
IBM Cognos Analytics 11.1.7 and 11.2.0 could allow a low level user to reas of the application that privileged user should only be allowed to view. IBM X-Force ID: 201087.
Published 2021-12-03 · Modified
6.5EPSS 0.009
CVE-2024-56340
IBM Cognos Analytics path traversal
Published 2025-02-28 · Modified
6.5EPSS 0.008
1 / 3Next →