IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.2 is vulnerable to injection attacks in application logging by not sanitizing user provided data. This could lead to further attacks against the system. IBM X-Force ID: 282956.
History

Wed, 02 Jul 2025 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Netapp
Netapp oncommand Insight
CPEs cpe:2.3:a:ibm:cognos_analytics:11.2.4:-:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:11.2.4:fixpack1:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:11.2.4:fixpack2:*:*:*:*:*:*
cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:*
Vendors & Products Netapp
Netapp oncommand Insight

Thu, 13 Feb 2025 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Ibm
Ibm cognos Analytics
CPEs cpe:2.3:a:ibm:cognos_analytics:*:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm cognos Analytics
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2025-02-13T17:40:45.804Z

Reserved: 2024-02-03T14:49:33.094Z

Link: CVE-2024-25047

cve-icon Vulnrichment

Updated: 2024-08-01T23:36:21.297Z

cve-icon NVD

Status : Analyzed

Published: 2024-05-02T21:16:11.330

Modified: 2025-07-02T15:41:45.863

Link: CVE-2024-25047

cve-icon Redhat

No data.