Vulnerabilities > IBM > Cognos Analytics > 12.0.3

DATE CVE VULNERABILITY TITLE RISK
2024-12-18 CVE-2024-25042 Cross-site Scripting vulnerability in IBM Cognos Analytics
IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 is potentially vulnerable to Cross Site Scripting (XSS).
network
low complexity
ibm CWE-79
6.1
2024-12-18 CVE-2024-41752 Cross-site Scripting vulnerability in IBM Cognos Analytics
IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 is vulnerable to HTML injection.
network
low complexity
ibm CWE-79
6.1
2024-12-18 CVE-2024-45082 Open Redirect vulnerability in IBM Cognos Analytics
IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 could allow a remote attacker to conduct phishing attacks, using an open redirect attack.
low complexity
ibm CWE-601
5.2
2024-09-22 CVE-2024-40703 Insufficiently Protected Credentials vulnerability in IBM Cognos Analytics and Cognos Analytics Reports
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and IBM Cognos Analytics Reports for iOS 11.0.0.7 could allow a local attacker to obtain sensitive information in the form of an API key.
local
low complexity
ibm CWE-522
5.5