VendorsIBMcognos_analyticsany version
Vulnerabilities

IBM Cognos Analytics any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

57CVEs
CVE-2021-38945
IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 could allow a remote attacker to upload arbitrary files, caused by improper content validation. IBM X-Force ID: 211238.
Published 2022-06-24 · Modified
9.8EPSS 0.017
CVE-2020-4302
IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to execute arbitrary code on the system, caused by a CSV injection. By persuading a victim to open a specially-crafted excel file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 176610.
Published 2020-10-12 · Modified
9.3EPSS 0.017
CVE-2019-4178
IBM Cognos Analytics 11 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request to write or view arbitrary files on the system. IBM X-Force ID: 158919.
Published 2019-04-15 · Modified
9.1EPSS 0.031
CVE-2022-38708
IBM Cognos Analytics server-side request forgery
Published 2022-12-19 · Modified
9.1EPSS 0.004
CVE-2024-51466
IBM Cognos Analytics expression language injection
Published 2024-12-20 · Analyzed
9.0EPSS 0.006
CVE-2021-29756
IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site request forgery (CSRF) in the My Inbox page which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 202167.
Published 2021-12-03 · Modified
8.8EPSS 0.006
CVE-2024-25047
IBM Cognos Analytics log injection
Published 2024-05-02 · Analyzed
8.6EPSS 0.006
CVE-2020-4388
IBM Cognos Analytics 11.0 and 11.1 could be vulnerable to a denial of service attack by failing to catch exceptions in a servlet also exposing debug information could also be used in future attacks. IBM X-Force ID: 179270.
Published 2020-10-12 · Modified
8.2EPSS 0.013
CVE-2025-3633
IBM Cognos Analytics is affected by multiple security vulnerabilities
Published 2026-05-27 · Analyzed
8.2EPSS 0.003
CVE-2022-36773
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 233571.
Published 2022-09-01 · Modified
8.1EPSS 0.019
CVE-2024-40695
IBM Cognos Analytics file upload
Published 2024-12-20 · Analyzed
8.0EPSS 0.004
CVE-2025-36126
IBM Cognos Analytics is affected by Cross-site scripting.
Published 2026-05-26 · Analyzed
7.6EPSS 0.002
CVE-2022-30614
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to a denial of service via email flooding caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume all available CPU resources. IBM X-Force ID: 227591.
Published 2022-09-01 · Modified
7.5EPSS 0.017
CVE-2021-20470
IBM Cognos Analytics 11.1.7 and 11.2.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 196339.
Published 2021-12-03 · Modified
7.5EPSS 0.014
CVE-2022-43883
IBM Cognos Analytics data manipulation
Published 2022-12-19 · Modified
7.5EPSS 0.006
CVE-2025-25032
IBM Cognos Analytics denial of service
Published 2025-06-11 · Analyzed
7.5EPSS 0.004
CVE-2024-49352
IBM Cognos Anaytics XML external entity injection
Published 2025-02-05 · Analyzed
7.1EPSS 0.005
CVE-2024-45082
IBM Cognos Analytics HTTP open redirection
Published 2024-12-18 · Analyzed
6.8EPSS 0.002
CVE-2022-34357
IBM Cognos Analytics Mobile Server denial of service
Published 2024-02-24 · Analyzed
6.5EPSS 0.012
CVE-2021-29768
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a low level user to obtain sensitive information from the details of the 'Cloud Storage' page for which they should not have access. IBM X-Force ID: 202682.
Published 2022-06-24 · Modified
6.5EPSS 0.010
CVE-2021-20461
IBM Cognos Analytics 10.0 and 11.1 is susceptible to a weakness in the implementation of the System Appearance configuration setting. An attacker could potentially bypass business logic to modify the appearance and behavior of the application. IBM X-Force ID: 196770.
Published 2021-06-30 · Modified
6.5EPSS 0.010
CVE-2021-29716
IBM Cognos Analytics 11.1.7 and 11.2.0 could allow a low level user to reas of the application that privileged user should only be allowed to view. IBM X-Force ID: 201087.
Published 2021-12-03 · Modified
6.5EPSS 0.009
CVE-2024-56340
IBM Cognos Analytics path traversal
Published 2025-02-28 · Modified
6.5EPSS 0.008
CVE-2025-0823
IBM MQ path traversal
Published 2025-02-28 · Analyzed
6.5EPSS 0.006
CVE-2021-29823
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 204465.
Published 2022-09-01 · Modified
6.5EPSS 0.005
CVE-2022-34339
"IBM Cognos Analytics 11.2.1, 11.2.0, 11.1.7 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 229963."
Published 2022-11-03 · Modified
6.5EPSS 0.004
CVE-2021-20468
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 196825.
Published 2022-09-01 · Modified
6.5EPSS 0.004
CVE-2020-4301
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 176609.
Published 2022-09-01 · Modified
6.5EPSS 0.004
CVE-2024-52900
IBM Cognos Analytics cross-site scripting
Published 2025-06-28 · Analyzed
6.4EPSS 0.002
CVE-2021-39045
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a local attacker to obtain information due to the autocomplete feature on password input fields. IBM X-Force ID: 214345.
Published 2022-09-01 · Modified
6.2EPSS 0.002
CVE-2021-20493
IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 197794.
Published 2021-12-03 · Modified
6.1EPSS 0.009
CVE-2021-39047
IBM Planning Analytics 2.0 and IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 214349.
Published 2022-06-24 · Modified
6.1EPSS 0.009
CVE-2023-38359
IBM Cognos Analytics cross-site scripting
Published 2024-02-24 · Analyzed
6.1EPSS 0.007
CVE-2022-39160
IBM Cognos Analytics cross-site scripting
Published 2022-12-19 · Modified
6.1EPSS 0.004
CVE-2024-25042
IBM Cognos Analytics cross-site scripting
Published 2024-12-18 · Analyzed
6.1EPSS 0.003
CVE-2024-41752
IBM Cognos Analytics HTML injection
Published 2024-12-18 · Analyzed
6.1EPSS 0.003
CVE-2021-29867
IBM Cognos Analytics 11.1.7 and 11.2.0 could allow an authenticated to view or edit a Jupyter notebook that they should not have access to. IBM X-Force ID: 206212.
Published 2021-12-03 · Modified
5.5EPSS 0.008
CVE-2025-0917
IBM Cognos Analytics cross-site scripting
Published 2025-06-11 · Analyzed
5.5EPSS 0.002
CVE-2021-39009
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 stores user credentials in plain clear text which can be read by a local privileged user. IBM X-Force ID: 213554.
Published 2022-09-01 · Modified
5.5EPSS 0.002
CVE-2024-40703
IBM Cognos Analytics information disclosure
Published 2024-09-22 · Analyzed
5.5EPSS 0.001
1 / 2Next →