VendorsIBMcognos_analyticsall versions
Vulnerabilities

IBM Cognos Analytics

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

105CVEs
CVE-2016-3031
IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1998887.
Published 2017-04-05 · Modified
5.4EPSS 0.005
CVE-2016-3032
IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 114516.
Published 2017-05-10 · Modified
5.4EPSS 0.005
CVE-2023-25929
IBM Cognos Analytics cross-site scripting
Published 2023-07-22 · Modified
5.4EPSS 0.005
CVE-2023-35011
IBM Cognos Analytics server-side request forgey
Published 2023-08-16 · Modified
5.4EPSS 0.005
CVE-2024-25041
IBM Cognos Analytics cross-site scripting
Published 2024-06-28 · Modified
5.4EPSS 0.004
CVE-2026-15995
IBM Cognos Analytics 12.1.3 general availability package contains a data integrity issue in the Agentic AI assistant that may cause incorrect report summaries or report-processing errors under concurrent use
Published 2026-07-17 · Analyzed
5.4EPSS 0.002
CVE-2016-9711
IBM Predictive Solutions Foundation (IBM Cognos Analytics 11.0) reveals sensitive information in detailed error messages that could aid an attacker in further attacks against the system. IBM X-Force ID: 119619.
Published 2018-03-22 · Modified
5.3EPSS 0.017
CVE-2021-29719
IBM Cognos Analytics 11.1.7 and 11.2.0 could be vulnerable to client side vulnerabilties due to a web response specifying an incorrect content type. IBM X-Force ID: 201091
Published 2021-12-03 · Modified
5.3EPSS 0.012
CVE-2023-35009
IBM Cognos Analytics information disclosure
Published 2023-08-16 · Modified
5.3EPSS 0.010
CVE-2019-4366
IBM Cognos Analytics 11.0 and 11.1 is susceptible to an information disclosure vulnerability where an attacker could gain access to cached browser data. IBM X-Force ID: 161748.
Published 2020-08-03 · Modified
5.3EPSS 0.007
CVE-2022-43887
IBM Cognos Analytics information disclosure
Published 2022-12-19 · Modified
5.3EPSS 0.005
CVE-2023-30996
IBM Cognos Analytics cross-origin resource sharing
Published 2024-02-24 · Analyzed
5.3EPSS 0.004
CVE-2025-0923
IBM Cognos Analytics information disclosure
Published 2025-06-11 · Analyzed
5.3EPSS 0.003
CVE-2019-4589
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to privlege escalation where the "My schedules and subscriptions" page is visible and accessible to a less privileged user. IBM X-Force ID: 167449.
Published 2020-08-03 · Modified
4.6EPSS 0.007
CVE-2019-4729
IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 172519.
Published 2020-04-27 · Modified
4.3EPSS 0.016
CVE-2019-4722
IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain sensitive information via a stack trace due to mishandling of certain error conditions. IBM X-Force ID: 172128.
Published 2021-05-31 · Modified
4.3EPSS 0.014
CVE-2016-0398
IBM Cognos Analytics (CA) 11.0 before 11.0.2 allows remote attackers to conduct content-spoofing attacks via a crafted URL.
Published 2016-07-02 · Modified
4.3EPSS 0.012
CVE-2021-38905
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 could allow an authenticated user to view report pages that they should not have access to. IBM X-Force ID: 209697.
Published 2022-04-22 · Modified
4.3EPSS 0.009
CVE-2019-4334
IBM Cognos Analytics 11.0 and 11.1 could reveal sensitive information to an authenticated user that could be used in future attacks against the system. IBM X-Force ID: 161271.
Published 2019-11-09 · Modified
4.3EPSS 0.009
CVE-2021-29824
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to priviledge escalation where a lower level user could have read access to to the 'Data Connections' page to which they don't have access. IBM X-Force ID: 204468.
Published 2022-04-22 · Modified
4.3EPSS 0.009
CVE-2019-4231
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 159356.
Published 2019-12-20 · Modified
4.3EPSS 0.007
CVE-2023-32344
IBM Cognos Analytics cross-site request forgery
Published 2024-02-24 · Analyzed
4.3EPSS 0.004
CVE-2017-1783
IBM Cognos Analytics 11.0 could allow a local user to change parameters set from the Cognos Analytics menus without proper authentication. IBM X-Force ID: 136857.
Published 2018-01-29 · Modified
4.0EPSS 0.005
CVE-2020-4951
IBM Cognos Analytics 11.1.7 and 11.2.0 contains locally cached browser data, that could allow a local attacker to obtain sensitive information.
Published 2021-10-15 · Modified
4.0EPSS 0.003
CVE-2018-1842
IBM Cognos Analytics 11 Configuration tool, under certain circumstances, will bypass OIDC namespace signature verification on its id_token. IBM X-Force ID: 150902.
Published 2018-11-09 · Modified
3.6EPSS 0.003
← Prev3 / 3