IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 stores source code on the web server that could aid in further attacks against the system.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NIBM Cognos Analytics
APPIbm11.2.411.2.0 – 11.2.412.0.0 – 12.0.4
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References
Related vulnerabilities
CVE-2024-51466CRITICAL9.0PL ✓same product
IBM Cognos Analytics — podatność Expression Language Injection (EL Injection)
CVE-2021-38945CRITICAL9.8PL ✓same product
IBM Cognos Analytics — nieograniczony upload plików (CWE-434)
CVE-2020-4561CRITICAL10.0PL ✓same product
IBM Cognos Analytics – nieuwierzytelniony dostęp do DQM API (odczyt/zapis plików)
CVE-2020-4377CRITICAL9.1PL ✓same product
IBM Cognos Analytics — atak XXE umożliwiający wyciek danych
CVE-2025-25032HIGH7.5same product
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 could ...