Skip to main content

Vendor/product archive

ibm / cognos_business_intelligence CVEs

Beta · best-effort

29 CVEs tagged to ibm / cognos_business_intelligence1 Critical, 4 High, 18 Medium, 6 Low, 0 Unrated.

CVE-2018-1934

Published Dec 20, 2019

IBM Cognos Business Intelligence 10.2.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-1764

Published Apr 23, 2018

IBM Cognos Business Intelligence 10.2, 10.2.1, 10.2.1.1, and 10.2.2, under specialized circumstances, could expose plain text credentials to a local user. IBM X-Force ID: 136149.

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2017-1486

Published Apr 23, 2018

IBM Cognos Business Intelligence 10.2, 10.2.1, 10.2.1.1, and 10.2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in th…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-0254

Published Jun 7, 2017

IBM Cognos Business Intelligence 10.1 and 10.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote auth…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-3038

Published Apr 17, 2017

IBM Cognos TM1 10.1 and 10.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended fun…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-3037

Published Apr 17, 2017

IBM Cognos TM1 10.1 and 10.2 provides a service to return the victim's password with a valid session key. An authenticated attacker with user interaction could obtain this sensiti…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-3036

Published Apr 17, 2017

IBM Cognos TM1 10.1 and 10.2 is vulnerable to a denial of service, caused by a stack-based buffer overflow when parsing packets. A remote attacker could exploit this vulnerability…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-8960

Published Mar 27, 2017

IBM Cognos Business Intelligence 10.2 could allow a user with lower privilege Capabilities to adopt the Capabilities of a higher-privilege user by intercepting the higher-privileg…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9985

Published Mar 8, 2017

IBM Cognos Server 10.1.1 and 10.2 stores highly sensitive information in log files that could be read by a local user. IBM Reference #: 1999671.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-0218

Published Feb 1, 2017

IBM Cognos Business Intelligence and IBM Cognos Analytics are vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could ex…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-0346

Published Jul 3, 2016

Cross-site scripting (XSS) vulnerability in IBM Cognos Business Intelligence 10.2 before IF20, 10.2.1 before IF17, 10.2.1.1 before IF16, 10.2.2 before IF12, and 10.1.1 before IF19…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-0221

Published Jul 3, 2016

Cross-site scripting (XSS) vulnerability in IBM Cognos TM1, as used in IBM Cognos Business Intelligence 10.2 before IF20, 10.2.1 before IF17, 10.2.1.1 before IF16, 10.2.2 before I…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-6145

Published Dec 12, 2014

Cross-site scripting (XSS) vulnerability in the server in IBM Cognos Business Intelligence 10.1 before IF10, 10.1.1 before IF9, 10.2 before IF11, 10.2.1 before IF8, and 10.2.1.1 b…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-0861

Published Feb 22, 2014

Cross-site scripting (XSS) vulnerability in the server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1 before IF6, 10.1.1 before IF5, 10.2 before IF7, 10.2.1 before IF4, and…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-0854

Published Feb 22, 2014

The server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1 before IF6, 10.1.1 before IF5, 10.2 before IF7, 10.2.1 before IF4, and 10.2.1.1 before IF4 allows remote authentica…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6732

Published Feb 22, 2014

Cross-site scripting (XSS) vulnerability in the server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1 before IF6, 10.1.1 before IF5, 10.2 before IF7, 10.2.1 before IF4, and…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4034

Published Nov 18, 2013

IBM Cognos Business Intelligence 8.4.1 before IF3, 10.1.0 before IF4, 10.1.1 before IF4, 10.2.0 before IF4, 10.2.1 before IF2, and 10.2.1.1 before IF1 allows remote authenticated…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3030

Published Nov 18, 2013

The servlet gateway in IBM Cognos Business Intelligence 8.4.1 before IF3, 10.1.0 before IF4, 10.1.1 before IF4, 10.2.0 before IF4, 10.2.1 before IF2, and 10.2.1.1 before IF1 allow…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-2988

Published Aug 27, 2013

Absolute path traversal vulnerability in the server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1, 10.1.1, 10.2, and 10.2.1 allows remote authenticated users to read files…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-2978

Published Aug 27, 2013

Absolute path traversal vulnerability in the server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1, 10.1.1, 10.2, and 10.2.1 allows remote authenticated users to read files…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-0586

Published Aug 27, 2013

Cross-site scripting (XSS) vulnerability in the server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1, 10.1.1, 10.2, and 10.2.1 allows remote authenticated users to inject a…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-4858

Published Mar 5, 2013

IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 does not properly validate Java serialized input, which allows remo…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-4840

Published Mar 5, 2013

IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 allows remote attackers to conduct XPath injection attacks, and cal…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4837

Published Mar 5, 2013

IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 allows remote authenticated users to conduct XPath injection attack…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4836

Published Mar 5, 2013

Cross-site scripting (XSS) vulnerability in IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 allows remote authentic…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort
Showing 1-25 of 29 CVEsPage 1 of 2