VendorsIBMcognos_controllerall versions
Vulnerabilities

IBM Cognos Controller

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

52CVEs
CVE-2020-4879
IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could allow a remote attacker to bypass security restrictions, caused by improper validation of authentication cookies. IBM X-Force ID: 190847.
Published 2022-01-21 · Modified
9.8EPSS 0.015
CVE-2020-4877
IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could be vulnerable to unauthorized modifications by using public fields in public classes. IBM X-Force ID: 190843.
Published 2022-01-21 · Modified
9.8EPSS 0.009
CVE-2023-38724
IBM Cognos Controller SQL injection
Published 2024-05-03 · Analyzed
9.8EPSS 0.005
CVE-2024-40691
IBM Cognos Controller file upload
Published 2024-12-03 · Analyzed
9.8EPSS 0.004
CVE-2024-25019
IBM Cognos Controller file upload
Published 2024-12-03 · Analyzed
9.8EPSS 0.003
CVE-2024-25020
IBM Cognos Controller file upload
Published 2024-12-03 · Analyzed
9.8EPSS 0.003
CVE-2024-28777
IBM Cognos Controller code execution
Published 2025-02-19 · Analyzed
8.8EPSS 0.006
CVE-2024-52902
IBM Cognos Controller information disclosure
Published 2025-02-19 · Analyzed
8.8EPSS 0.004
CVE-2023-40695
IBM Cognos Controller session fixation
Published 2024-05-03 · Analyzed
8.8EPSS 0.004
CVE-2020-4875
IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 190838.
Published 2022-01-21 · Modified
8.2EPSS 0.017
CVE-2020-4876
IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 190839.
Published 2022-01-21 · Modified
8.2EPSS 0.017
CVE-2023-47160
IBM Cognos Controller XML external entity injection
Published 2025-02-19 · Analyzed
8.2EPSS 0.005
CVE-2024-40702
IBM Cognos Controller improper certificate validation
Published 2025-01-07 · Analyzed
8.2EPSS 0.003
CVE-2020-4685
A low level user of IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, 10.4.1, and 10.4.2 who has Administration rights to the server where the application is installed, can escalate their privilege from Low level to Super Admin and gain access to Create/Update/Delete any level of user in Cognos Controller. IBM X-Force ID: 186625.
Published 2020-11-11 · Modified
8.0EPSS 0.014
CVE-2024-45084
IBM Cognos Controller CSV injection
Published 2025-02-19 · Modified
8.0EPSS 0.004
CVE-2019-4175
IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, and 10.4.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 158880.
Published 2019-09-17 · Modified
7.5EPSS 0.010
CVE-2020-4874
IBM Cognos Controller information disclosure
Published 2024-05-03 · Analyzed
7.5EPSS 0.003
CVE-2023-40696
IBM Cognos Controller information disclosure
Published 2024-05-03 · Analyzed
7.5EPSS 0.003
CVE-2024-41777
IBM Cognos Controller hard coded credentials
Published 2024-12-03 · Analyzed
7.5EPSS 0.003
CVE-2025-36326
IBM Controller information disclosure
Published 2025-09-26 · Analyzed
7.5EPSS 0.002
CVE-2024-41775
IBM Cognos Controller information disclosure
Published 2024-12-03 · Analyzed
7.5EPSS 0.002
CVE-2021-20451
IBM Cognos Controller SQL injection
Published 2024-05-03 · Analyzed
7.2EPSS 0.005
CVE-2019-4173
IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 could allow a remote attacker to obtain sensitive information, caused by a flaw in the HTTP OPTIONS method, aka Optionsbleed. By sending an OPTIONS HTTP request, a remote attacker could exploit this vulnerability to read secret data from process memory and obtain sensitive information. IBM X-Force ID: 158878.
Published 2019-06-17 · Modified
6.5EPSS 0.018
CVE-2024-28778
IBM Cognos Controller information disclosure
Published 2025-01-07 · Analyzed
6.5EPSS 0.005
CVE-2025-33079
IBM Controller information disclosure
Published 2025-05-27 · Analyzed
6.5EPSS 0.003
CVE-2025-36015
IBM Controller Denial of Service
Published 2025-12-08 · Analyzed
6.5EPSS 0.003
CVE-2024-45081
IBM Cognos Controller incorrect authorization
Published 2025-02-19 · Analyzed
6.5EPSS 0.003
CVE-2024-41776
IBM Cognos Controller cross-site request forgery
Published 2024-12-03 · Analyzed
6.5EPSS 0.002
CVE-2021-29892
IBM Cognos Controller information disclosure
Published 2024-12-03 · Analyzed
5.9EPSS 0.003
CVE-2024-28780
IBM Cognos Controller information disclosure
Published 2025-02-19 · Analyzed
5.9EPSS 0.002
CVE-2019-4136
IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 158332.
Published 2019-06-17 · Modified
5.4EPSS 0.007
CVE-2024-28776
IBM Cognos Controller cross-site scripting
Published 2025-02-19 · Analyzed
5.4EPSS 0.002
CVE-2019-4176
IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 could allow a remote attacker to bypass security restrictions, caused by an error related to insecure HTTP Methods. An attacker could exploit this vulnerability to gain access to the system. IBM X-Force ID: 158881.
Published 2019-06-17 · Modified
5.3EPSS 0.019
CVE-2019-4412
IBM Cognos Controller stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 162659.
Published 2019-11-09 · Modified
5.3EPSS 0.010
CVE-2022-22364
IBM Cognos Controller security bypass
Published 2024-05-03 · Analyzed
5.3EPSS 0.005
CVE-2021-20556
IBM Cognos Controller information disclosure
Published 2024-05-03 · Analyzed
5.3EPSS 0.005
CVE-2023-23474
IBM Cognos Controller information disclosure
Published 2024-05-03 · Analyzed
5.3EPSS 0.004
CVE-2023-28952
IBM Cognos Controller log injection
Published 2024-05-03 · Analyzed
5.3EPSS 0.004
CVE-2024-25035
IBM Cognos Controller information disclosure
Published 2024-12-03 · Analyzed
5.3EPSS 0.003
CVE-2022-39163
IBM Cognos Controller HTTP response smuggling
Published 2025-03-26 · Analyzed
4.7EPSS 0.002
1 / 2Next →