Known vulnerabilities in IBM Cognos Analytics - page 10

Software CPE: cpe:2.3:a:ibm_corporation:ibm_cognos_analytics:*:*:*:*:*:*:*:*
Total vulnerabilities: 206
Public exploits: 21
Known exploited (KEV): 5
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting IBM Cognos Analytics IBM Cognos Analytics is affected by 206 known vulnerabilities: 4 critical, 31 high, 108 medium, 63 low Critical High Medium Low

Vulnerabilities (206)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU66865 - Information Exposure Through Log Files
CVE-2022-24758
CWE-532 Low
No
No
11.1.7.6, 11.2.3 30.08.2022 SB2022033123
SB2022083035
SB2022120724
#VU62361 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-43138
CWE-94 Medium
No
No
11.1.7.6, 11.2.3 15.04.2022 SB2022041532
SB2022041533
SB2022062103
and 33 more
#VU61675 - Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVE-2022-0391
CWE-93 Medium
No
No
11.1.7.6, 11.2.3 29.03.2022 SB2022032903
SB2022032905
SB2022032907
and 49 more
#VU59098 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-44832
CWE-94 Medium
No
No
11.0.13.5, 11.1.7.8, 11.2.1.3 28.12.2021 SB2021122816
SB2021123002
SB2022010601
and 197 more
#VU59051 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2021-45105
CWE-835 Medium
Available
No
11.0.13.5, 11.1.7.8, 11.2.1.3 18.12.2021 SB2021121802
SB2021121903
SB2021122011
and 169 more
#VU58976 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-45046
CWE-94 High
Available
Exploited
11.0.13.4, 11.1.7.7, 11.2.1.2 15.12.2021 SB2021121504
SB2021121511
SB2021121512
and 178 more
#VU58816 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-44228
CWE-94 Critical
Available
Exploited
11.0.13.4, 11.1.7.7, 11.2.1.2 10.12.2021 SB2021121003
SB2021121101
SB2021121201
and 338 more
#VU29228 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-4051
CWE-79 Low
No
No
11.1.7.6, 11.2.3 24.06.2020 SB2020062408
SB2022082433
SB2022120724
and 7 more
#VU15752 - Permissions, Privileges, and Access Controls
CVE-2018-1842
CWE-264 Low
No
No
11.0.13 06.11.2018 SB2018110715
#VU12311 - Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
CVE-2018-1426
CWE-338 Low
No
No
11.0.13 01.05.2018 SB2018050202
SB2018060802
SB2018061409
and 5 more
#VU12310 - Integer overflow
CVE-2018-1427
CWE-190 Low
No
No
11.0.13 01.05.2018 SB2018050202
SB2018060802
SB2018061409
and 5 more
#VU12309 - Use of a Broken or Risky Cryptographic Algorithm
CVE-2018-1428
CWE-327 Low
No
No
11.0.13 01.05.2018 SB2018050202
SB2018060802
SB2018061409
and 4 more
#VU12308 - Weak Password Requirements
CVE-2018-1447
CWE-521 Low
No
No
11.0.13 01.05.2018 SB2018050202
SB2018060802
SB2018061409
and 4 more
#VU11294 - Resource exhaustion
CVE-2018-0739
CWE-400 Low
No
No
11.0.13 28.03.2018 SB2018032804
SB2018032903
SB2018033002
and 35 more
#VU11285 - Data Handling
CVE-2017-12624
CWE-19 Low
No
No
11.0.13 27.03.2018 SB2017111431
SB2018072004
SB2018110715
and 5 more
#VU9607 - Improper input validation
CVE-2017-15095
CWE-20 High
No
No
11.0.13 08.12.2017 SB2017121101
SB2017111609
SB2018051424
and 27 more
#VU9594 - Improper input validation
CVE-2017-3737
CWE-20 Medium
No
No
11.0.13 08.12.2017 SB2017120804
SB2017120902
SB2017121001
and 21 more
#VU9128 - Deserialization of Untrusted Data
CVE-2017-7525
CWE-502 High
Available
No
11.0.13 08.11.2017 SB2017110807
SB2017102005
SB2017120205
and 39 more
#VU5442 - Cryptographic Issues
CVE-2017-3732
CWE-310 Low
No
No
11.0.13 27.01.2017 SB2017012701
SB2017022301
SB2017021407
and 25 more
#VU1622 - Double Free
CVE-2016-0705
CWE-415 Low
No
No
11.0.13 21.12.2016 SB2018050202
SB2018061409
SB2018061506
and 18 more


Showing elements 181 - 200 out of 206