IBM Cognos Analytics 11.2.0 through 12.2.4 Fix Pack 5 and 12.0.0 through 12.0.4 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
History

Tue, 01 Jul 2025 18:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:cognos_analytics:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:11.2.4:-:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:11.2.4:fixpack1:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:11.2.4:fixpack2:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:11.2.4:fixpack3:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:11.2.4:fixpack4:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:11.2.4:fixpack5:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:11.2.4:interim_fix_1:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:11.2.4:interim_fix_2:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:11.2.4:interim_fix_3:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:11.2.4:interim_fix_4:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:11.2.4:interim_fix_5:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:12.0.4:-:*:*:*:*:*:*

Mon, 30 Jun 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 28 Jun 2025 01:15:00 +0000

Type Values Removed Values Added
Description IBM Cognos Analytics 11.2.0 through 12.2.4 Fix Pack 5 and 12.0.0 through 12.0.4 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Title IBM Cognos Analytics cross-site scripting
First Time appeared Ibm
Ibm cognos Analytics
Weaknesses CWE-79
CPEs cpe:2.3:a:ibm:cognos_analytics:11.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:11.2.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:11.2.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:11.2.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:11.2.4:fix_pack5:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:12.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:12.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:12.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:12.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:12.0.4:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm cognos Analytics
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published: 2025-06-28T00:59:23.758Z

Updated: 2025-06-30T13:37:28.289Z

Reserved: 2024-11-17T14:25:57.178Z

Link: CVE-2024-52900

cve-icon Vulnrichment

Updated: 2025-06-30T13:37:18.251Z

cve-icon NVD

Status : Analyzed

Published: 2025-06-28T01:15:24.957

Modified: 2025-07-01T18:07:20.727

Link: CVE-2024-52900

cve-icon Redhat

No data.