Known vulnerabilities in Cognos Analytics Mobile (Android) - page 2

Software CPE: cpe:2.3:a:ibm_corporation:cognos_analytics_mobile_android:*:*:*:*:*:*:*:*
Total vulnerabilities: 49
Public exploits: 6
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Cognos Analytics Mobile (Android) Cognos Analytics Mobile (Android) is affected by 49 known vulnerabilities: 1 critical, 2 high, 34 medium, 12 low Critical High Medium Low

Vulnerabilities (49)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU99864 - Improper Certificate Validation
CVE-2023-38009
CWE-295 Low
No
No
1.1.20 06.11.2024 SB2024110620
SB2024110829
#VU99863 - Exposure of sensitive information to an unauthorized actor
CVE-2022-43383
CWE-200 Low
No
No
1.1.20 06.11.2024 SB2024110620
SB2024110829
#VU99862 - Improper Link Resolution Before File Access ('Link Following')
CVE-2022-36943
CWE-59 High
No
No
1.1.20 06.11.2024 SB2024110619
SB2024110620
SB2024110829
#VU99859 - Inefficient Regular Expression Complexity
CVE-2023-25166
CWE-1333 Low
No
No
1.1.20 06.11.2024 SB2024110617
SB2024110620
SB2024110829
#VU98132 - Inefficient Regular Expression Complexity
CVE-2024-45296
CWE-1333 Low
No
No
1.1.20 08.10.2024 SB2024100822
SB2024100823
SB2024100826
and 87 more
#VU96970 - Resource exhaustion
CVE-2024-43398
CWE-400 Medium
No
No
1.1.20 10.09.2024 SB2024091006
SB2024091007
SB2024091008
and 28 more
#VU95816 - Server-Side Request Forgery (SSRF)
CVE-2024-29415
CWE-918 Medium
Available
No
1.1.20 13.08.2024 SB2024081345
SB2024082612
SB2024082760
and 13 more
#VU94363 - Improper input validation
CVE-2024-39908
CWE-20 Medium
No
No
1.1.20 16.07.2024 SB2024071616
SB2024083015
SB2024091009
and 22 more
#VU94361 - Improper input validation
CVE-2024-35176
CWE-20 Medium
Available
No
1.1.20 16.07.2024 SB2024071615
SB2024071914
SB2024072112
and 19 more
#VU94329 - NULL Pointer Dereference
CVE-2024-37890
CWE-476 Medium
No
No
1.1.20 15.07.2024 SB2024071508
SB2024071933
SB2024081608
and 32 more
#VU92406 - Incorrect Regular Expression
CVE-2024-4067
CWE-185 Medium
No
No
1.1.20 20.06.2024 SB20240620121
SB2024062832
SB2024070501
and 41 more
#VU86944 - Server-Side Request Forgery (SSRF)
CVE-2023-42282
CWE-918 Medium
No
No
1.1.20 01.03.2024 SB2024030127
SB2024030148
SB2024030415
and 28 more
#VU83234 - Incorrect Comparison
CVE-2023-45133
CWE-697 Low
No
No
1.1.20 17.11.2023 SB2023111710
SB2023111712
SB2023113028
and 24 more
#VU78932 - Incorrect Regular Expression
CVE-2022-25883
CWE-185 Medium
No
No
1.1.20 03.08.2023 SB2023080361
SB2023080362
SB2023081514
and 73 more
#VU75603 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2023-0842
CWE-1321 Medium
No
No
1.1.20 01.05.2023 SB2023050113
SB2023050917
SB2023052413
and 12 more
#VU72033 - Incorrect Regular Expression
CVE-2023-22467
CWE-185 Medium
No
No
1.1.20 07.02.2023 SB2023020783
SB2023020793
SB2023020834
and 9 more
#VU71577 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-46175
CWE-94 Medium
No
No
1.1.20 26.01.2023 SB2023012644
SB2023012645
SB2023013117
and 44 more
#VU64030 - Resource exhaustion
CVE-2021-44906
CWE-400 High
No
No
1.1.20 07.06.2022 SB2022060836
SB2022062103
SB2022062203
and 52 more
#VU63702 - Allocation of Resources Without Limits or Throttling
CVE-2020-15168
CWE-770 Medium
No
No
1.1.20 26.05.2022 SB2020091032
SB2022052615
SB2022060618
and 12 more
#VU61471 - Exposure of sensitive information to an unauthorized actor
CVE-2022-0235
CWE-200 Low
No
No
1.1.20 20.03.2022 SB2022032001
SB2022032002
SB2022032009
and 35 more


Showing elements 21 - 40 out of 49