PT-2021-3235 · Ibm · Ibm Cognos Analytics

Published

2021-05-31

·

Updated

2022-07-12

·

CVE-2020-4520

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM Cognos Analytics versions 11.0 through 11.1
Description The issue is related to incorrect code generation management in the online service for business analytics. It allows a remote attacker to inject malicious HTML code, which executes when viewed by an authenticated victim.
Recommendations For IBM Cognos Analytics versions 11.0 through 11.1, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Code Injection

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-02947
CVE-2020-4520

Affected Products

Ibm Cognos Analytics