Vulnerabilities > IBM > Cognos Controller

DATE CVE VULNERABILITY TITLE RISK
2024-05-03 CVE-2021-20451 Unspecified vulnerability in IBM Cognos Controller 10.4.1/10.4.2/11.0.0
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to SQL injection.
network
low complexity
ibm
7.2
2024-05-03 CVE-2022-22364 Authentication Bypass by Spoofing vulnerability in IBM Cognos Controller 10.4.1/10.4.2/11.0.0
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to external service interaction attack, caused by improper validation of user-supplied input.
network
low complexity
ibm CWE-290
5.3
2024-05-03 CVE-2023-40695 Unspecified vulnerability in IBM Cognos Controller 10.4.1/10.4.2/11.0.0
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.
network
low complexity
ibm
8.8
2024-05-03 CVE-2021-20556 Information Exposure Through Discrepancy vulnerability in IBM Cognos Controller 10.4.1/10.4.2/11.0.0
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 could allow a remote user to enumerate usernames due to differentiating error messages on existing usernames.
network
low complexity
ibm CWE-203
5.3
2024-05-03 CVE-2023-23474 Unspecified vulnerability in IBM Cognos Controller 10.4.1/10.4.2/11.0.0
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser.
network
low complexity
ibm
5.3
2024-05-03 CVE-2023-28952 Improper Encoding or Escaping of Output vulnerability in IBM Cognos Controller 10.4.1/10.4.2/11.0.0
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to injection attacks in application logging by not sanitizing user provided data.
network
low complexity
ibm CWE-116
5.3
2024-05-03 CVE-2023-38724 Unspecified vulnerability in IBM Cognos Controller 10.4.1/10.4.2/11.0.0
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to SQL injection.
network
low complexity
ibm
critical
9.8
2024-05-03 CVE-2023-40696 Unspecified vulnerability in IBM Cognos Controller 10.4.1/10.4.2/11.0.0
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
network
low complexity
ibm
7.5
2024-05-03 CVE-2020-4874 Unspecified vulnerability in IBM Cognos Controller 10.4.1/10.4.2/11.0.0
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
network
low complexity
ibm
7.5
2022-01-21 CVE-2020-4875 XXE vulnerability in IBM Cognos Controller 10.4.0/10.4.1/10.4.2
IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data.
network
low complexity
ibm CWE-611
8.2