VendorsIBMcognos_analyticsany version
Vulnerabilities

IBM Cognos Analytics any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

57CVEs
CVE-2018-1413
IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138819.
Published 2018-05-07 · Modified
5.4EPSS 0.011
CVE-2019-4555
IBM Cognos Analytics 11.0 and 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 166204.
Published 2019-12-20 · Modified
5.4EPSS 0.008
CVE-2021-38909
IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 209706.
Published 2021-12-03 · Modified
5.4EPSS 0.007
CVE-2023-28530
IBM Cognos Analytics cross-site scripting
Published 2023-07-22 · Modified
5.4EPSS 0.007
CVE-2023-43051
IBM Cognos Analytics cross-site scripting
Published 2024-02-24 · Analyzed
5.4EPSS 0.006
CVE-2023-25929
IBM Cognos Analytics cross-site scripting
Published 2023-07-22 · Modified
5.4EPSS 0.005
CVE-2023-35011
IBM Cognos Analytics server-side request forgey
Published 2023-08-16 · Modified
5.4EPSS 0.005
CVE-2024-25041
IBM Cognos Analytics cross-site scripting
Published 2024-06-28 · Modified
5.4EPSS 0.004
CVE-2021-29719
IBM Cognos Analytics 11.1.7 and 11.2.0 could be vulnerable to client side vulnerabilties due to a web response specifying an incorrect content type. IBM X-Force ID: 201091
Published 2021-12-03 · Modified
5.3EPSS 0.012
CVE-2023-35009
IBM Cognos Analytics information disclosure
Published 2023-08-16 · Modified
5.3EPSS 0.010
CVE-2022-43887
IBM Cognos Analytics information disclosure
Published 2022-12-19 · Modified
5.3EPSS 0.005
CVE-2023-30996
IBM Cognos Analytics cross-origin resource sharing
Published 2024-02-24 · Analyzed
5.3EPSS 0.004
CVE-2025-0923
IBM Cognos Analytics information disclosure
Published 2025-06-11 · Analyzed
5.3EPSS 0.003
CVE-2019-4729
IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 172519.
Published 2020-04-27 · Modified
4.3EPSS 0.016
CVE-2019-4231
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 159356.
Published 2019-12-20 · Modified
4.3EPSS 0.007
CVE-2023-32344
IBM Cognos Analytics cross-site request forgery
Published 2024-02-24 · Analyzed
4.3EPSS 0.004
CVE-2018-1842
IBM Cognos Analytics 11 Configuration tool, under certain circumstances, will bypass OIDC namespace signature verification on its id_token. IBM X-Force ID: 150902.
Published 2018-11-09 · Modified
3.6EPSS 0.003
← Prev2 / 2