📦 Cognos Analytics

by Ibm

🔍 What is Cognos Analytics?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-51466

CRITICAL CVSS 9.0 Dec 20, 2024

IBM Cognos Analytics is vulnerable to Expression Language (EL) Injection, allowing remote attackers to execute malicious EL statements. This can lead to sensitive information disclosure, memory exhaus...

CVE-2021-38945

CRITICAL CVSS 9.8 Jun 24, 2022

CVE-2021-38945 is a critical vulnerability in IBM Cognos Analytics that allows remote attackers to upload arbitrary files due to improper content validation. This affects IBM Cognos Analytics versions...

CVE-2020-4561

CRITICAL CVSS 10.0 Jun 1, 2021

This vulnerability allows unauthenticated remote attackers to read and write files on IBM Cognos Analytics systems by exploiting the DQM API. It affects IBM Cognos Analytics 11.0 and 11.1 installation...

CVE-2020-4377

CRITICAL CVSS 9.1 Aug 3, 2020

IBM Cognos Analytics 11.0 and 11.1 contains an XML External Entity (XXE) vulnerability that allows remote attackers to read arbitrary files from the server or cause denial of service through resource ...

CVE-2025-25032

HIGH CVSS 7.5 Jun 11, 2025

This vulnerability in IBM Cognos Analytics allows authenticated users to send specially crafted requests that exhaust memory resources, causing denial of service. It affects multiple versions of IBM C...

CVE-2024-49352

HIGH CVSS 7.1 Feb 5, 2025

IBM Cognos Analytics is vulnerable to XML External Entity Injection (XXE), allowing attackers to read sensitive files from the server or cause denial of service through memory consumption. This affect...

CVE-2024-40695

HIGH CVSS 8.0 Dec 20, 2024

IBM Cognos Analytics has a file upload vulnerability that allows attackers to upload malicious executable files through the web interface without proper content validation. This affects IBM Cognos Ana...

CVE-2024-25047

HIGH CVSS 8.6 May 2, 2024

IBM Cognos Analytics versions 11.2.0-11.2.4 and 12.0.0-12.0.2 have improper input validation in application logging, allowing injection attacks. This could enable attackers to manipulate log data and ...

CVE-2021-38886

HIGH CVSS 8.8 Apr 22, 2022

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in IBM Cognos Analytics versions 11.1.7 and 11.2.0. An attacker could trick authenticated users into performing unauthorized action...

CVE-2021-29756

HIGH CVSS 8.8 Dec 3, 2021

This CSRF vulnerability in IBM Cognos Analytics allows attackers to trick authenticated users into performing unauthorized actions on the My Inbox page. It affects IBM Cognos Analytics 11.1.7 and 11.2...

CVE-2021-20470

HIGH CVSS 7.5 Dec 3, 2021

IBM Cognos Analytics versions 11.1.7 and 11.2.0 have a weak default password policy that doesn't enforce strong passwords. This makes user accounts vulnerable to brute-force attacks and credential gue...

CVE-2021-29745

HIGH CVSS 8.8 Oct 15, 2021

CVE-2021-29745 is a privilege escalation vulnerability in IBM Cognos Analytics where lower-level users can access the 'New Job' page, which should be restricted to higher-privileged users. This allows...

CVE-2019-4723

HIGH CVSS 7.5 Jun 1, 2021

IBM Cognos Analytics 11.0 and 11.1 have a vulnerability where the New Data Server Connection page incorrectly enables autocomplete for credential fields. This allows a remote attacker to potentially e...

CVE-2019-4730

HIGH CVSS 7.1 Jun 1, 2021

IBM Cognos Analytics 11.0 and 11.1 contains an XML External Entity (XXE) vulnerability that allows remote attackers to read arbitrary files from the server or cause denial of service through resource ...

CVE-2020-4300

HIGH CVSS 8.2 Jun 1, 2021

CVE-2020-4300 is an XML External Entity (XXE) vulnerability in IBM Cognos Analytics that allows remote attackers to read arbitrary files from the server or cause denial of service through resource con...

CVE-2020-4520

HIGH CVSS 8.8 Jun 1, 2021

This vulnerability allows remote attackers to inject malicious HTML code into IBM Cognos Analytics. When authenticated users view the compromised content, the attacker's code executes in their browser...

CVE-2025-0923

MEDIUM CVSS 5.3 Jun 11, 2025

IBM Cognos Analytics stores source code files on the web server that could be accessed by attackers. This vulnerability allows attackers to view sensitive source code that could reveal implementation ...

CVE-2025-0823

MEDIUM CVSS 6.5 Feb 28, 2025

This directory traversal vulnerability in IBM Cognos Analytics allows remote attackers to read arbitrary files on the server by sending specially crafted URL requests containing '../' sequences. Affec...

CVE-2024-41752

MEDIUM CVSS 5.4 Dec 18, 2024

IBM Cognos Analytics is vulnerable to HTML injection where attackers can inject malicious HTML that executes in victims' browsers. This affects IBM Cognos Analytics versions 11.2.0-11.2.4 and 12.0.0-1...

CVE-2024-40703

MEDIUM CVSS 5.5 Sep 22, 2024

This vulnerability allows a local attacker to obtain sensitive API key information from IBM Cognos Analytics and IBM Cognos Analytics Reports for iOS. Attackers could use this information to launch fu...

CVE-2024-25041

MEDIUM CVSS 5.4 Jun 28, 2024

This CVE describes a cross-site scripting (XSS) vulnerability in IBM Cognos Analytics that allows remote attackers to execute malicious scripts in users' browsers. The vulnerability exists in the Cogn...