PT-2024-20715 · Ibm · Ibm Cognos Analytics

Published

2024-12-18

·

Updated

2025-01-10

·

CVE-2024-25042

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions IBM Cognos Analytics versions 11.2.0 through 11.2.4 IBM Cognos Analytics versions 12.0.0 through 12.0.3
Description The issue is related to a Cross Site Scripting (XSS) vulnerability due to improper validation of column headings in Cognos Explorations. A remote attacker could execute malicious commands.
Recommendations For versions 11.2.0 through 11.2.4, consider disabling the Cognos Explorations feature until a patch is available. For versions 12.0.0 through 12.0.3, restrict access to the Cognos Explorations module to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-25042

Affected Products

Ibm Cognos Analytics