Known vulnerabilities in IBM Cognos Analytics - page 7

Software CPE: cpe:2.3:a:ibm_corporation:ibm_cognos_analytics:*:*:*:*:*:*:*:*
Total vulnerabilities: 206
Public exploits: 21
Known exploited (KEV): 5
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting IBM Cognos Analytics IBM Cognos Analytics is affected by 206 known vulnerabilities: 4 critical, 31 high, 108 medium, 63 low Critical High Medium Low

Vulnerabilities (206)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU86599 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-28530
CWE-79 Low
No
No
11.1.7 Fix Pack 7, 11.2.4 Fix Pack 2 20.02.2024 SB2024022002
#VU86598 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-25929
CWE-79 Low
No
No
11.1.7 Fix Pack 7, 11.2.4 Fix Pack 2 20.02.2024 SB2024022002
#VU83219 - Deserialization of Untrusted Data
CVE-2023-39410
CWE-502 Medium
No
No
11.1.7 Fix Pack 8, 11.2.4 FP3, 12.0.2 16.11.2023 SB2023111614
SB2023112014
SB2023112410
and 43 more
#VU80637 - Heap-based Buffer Overflow
CVE-2023-4863
CWE-122 Critical
Available
Exploited
- 11.09.2023 SB2023091178
SB2023091245
SB2023091265
and 137 more
#VU80323 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2023-26136
CWE-1321 High
No
No
11.1.7 Fix Pack 8, 11.2.4 FP3, 12.0.2 04.09.2023 SB2023090411
SB2023090423
SB2023090816
and 42 more
#VU78798 - Resource Management Errors
CVE-2023-3817
CWE-399 Low
No
No
11.1.7 Fix Pack 8, 11.2.4 FP3, 12.0.2 31.07.2023 SB2023073153
SB2023080268
SB2023080438
and 158 more
#VU75044 - Uncontrolled Recursion
CVE-2023-1370
CWE-674 Medium
No
No
11.1.7 Fix Pack 7, 11.2.4 Fix Pack 2 12.04.2023 SB2023041258
SB2023041259
SB2023041809
and 130 more
#VU72075 - Insecure Temporary File
CVE-2023-0482
CWE-377 Low
No
No
11.2.4 Fix Pack 2, 12.0.1 08.02.2023 SB2023020877
SB2023033003
SB2023033004
and 36 more
#VU70797 - Exposure of sensitive information to an unauthorized actor
CVE-2022-45787
CWE-200 Low
No
No
11.2.4 Fix Pack 2, 12.0.1 09.01.2023 SB2023010909
SB2023020878
SB2023031107
and 34 more
#VU70444 - Server-Side Request Forgery (SSRF)
CVE-2022-46364
CWE-918 Medium
No
No
11.2.4 Fix Pack 2, 12.0.1 20.12.2022 SB2022122009
SB2023011329
SB2023011707
and 67 more
#VU69675 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-24999
CWE-94 Medium
Available
No
11.1.7 Fix Pack 7, 11.2.4 Fix Pack 2 29.11.2022 SB2022112910
SB2022112911
SB2022112943
and 49 more
#VU68270 - Improper Authentication
CVE-2022-40664
CWE-287 High
Available
No
11.1.7.6, 11.2.4.1 IF1 12.10.2022 SB2022101258
SB2023011226
SB2023011842
and 3 more
#VU67178 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2020-28458
CWE-1321 Medium
Available
No
11.1.7 Fix Pack 8, 11.2.4 FP3, 12.0.2 12.09.2022 SB2022091209
SB2022102678
SB2023030252
and 2 more
#VU64030 - Resource exhaustion
CVE-2021-44906
CWE-400 High
No
No
11.1.7.6, 11.2.4.1 IF1 07.06.2022 SB2022060836
SB2022062103
SB2022062203
and 52 more
#VU62512 - Improper input validation
CVE-2021-3572
CWE-20 Medium
No
No
11.1.7 Fix Pack 8, 11.2.4 FP3, 12.0.2 22.04.2022 SB2022042257
SB2022042259
SB2021071390
and 51 more
#VU62402 - Improper input validation
CVE-2022-21443
CWE-20 Low
No
No
11.1.7 Fix Pack 8, 11.2.4 FP3, 12.0.2 19.04.2022 SB2022041944
SB2022041945
SB2022042102
and 109 more
#VU60621 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-23445
CWE-79 Low
No
No
11.1.7 Fix Pack 8, 11.2.4 FP3, 12.0.2 15.02.2022 SB2021092717
SB2022021511
SB2022080802
and 11 more
#VU56912 - Resource exhaustion
CVE-2021-29469
CWE-400 Low
No
No
11.1.7.6, 11.2.4 29.09.2021 SB2021042331
SB2022091307
SB2023013136
and 2 more
#VU55499 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2020-7789
CWE-78 High
No
No
11.1.7.6, 11.2.4.1 IF1 02.08.2021 SB2020121118
SB2021080213
SB2023071326
and 2 more
#VU26151 - Improper Control of Generation of Code ('Code Injection')
CVE-2020-7598
CWE-94 Medium
No
No
11.1.7.6, 11.2.4.1 IF1 18.03.2020 SB2020031805
SB2020072216
SB2020061308
and 18 more


Showing elements 121 - 140 out of 206