IBM Cognos Analytics versions 12.0.4 and 12.1.3 is affected by security vulnerabilities
Summary
| CVE | CVE-2026-7884 |
|---|---|
| State | PUBLISHED |
| Assigner | ibm |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-14 21:17:25 UTC |
| Updated | 2026-09-16 19:24:44 UTC |
| Description | IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 allows a non-privileged user to edit their given name and surname to include malicious JavaScript code. When an administrator later accesses the user account management panel and views that user's permissions, the malicious JavaScript code is executed. This could result in the cookies from the administrator being compromised. |
Risk And Classification
Primary CVSS: v3.1 5.4 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS: 0.002260000 probability, percentile 0.134190000 (date 2026-09-16)
Problem Types: CWE-79 | CWE-79 CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 5.4 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
| 3.1 | CNA | CVSS | 5.4 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
LowUser Interaction
RequiredScope
ChangedConfidentiality
LowIntegrity
LowAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | IBM | Cognos Analytics | affected 12.1.0 12.1.3 FP1 semver | Not specified |
| CNA | IBM | Cognos Analytics | affected 12.0.4 12.0.4 FP2 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.ibm.com/support/pages/node/7287209 | [email protected] | www.ibm.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
Solutions
CNA: IBM strongly recommends addressing the vulnerability now. Affected Product(s)Version(s)Fix VersionIBM Cognos Analytics12.1.0, 12.1.1, 12.1.2, 12.1.3, 12.1.3 FP1 12.1.3 FP2 https://www.ibm.com/support/pages/node/7283969 IBM Cognos Analytics12.0.4 - 12.0.4 FP2 12.0.4 FP3 https://www.ibm.com/support/pages/node/7269268
There are currently no legacy QID mappings associated with this CVE.