{"api_version":"1","generated_at":"2026-06-04T09:40:53+00:00","cve":"CVE-2025-36126","urls":{"html":"https://cve.report/CVE-2025-36126","api":"https://cve.report/api/cve/CVE-2025-36126.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2025-36126","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2025-36126"},"summary":{"title":"IBM Cognos Analytics is affected by Cross-site scripting.","description":"IBM Cognos Analytics 11.2.0, 12.0, and 12.1.0 and IBM Cognos Transformer 12.0, 11.2.4, and 12.1.0 is vulnerable to stored cross-site scripting (XSS) in Cognos Adminstration. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.","state":"PUBLISHED","assigner":"ibm","published_at":"2026-05-26 17:16:28","updated_at":"2026-06-01 17:30:40"},"problem_types":["CWE-79","CWE-79 CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"],"metrics":[{"version":"3.1","source":"nvd@nist.gov","type":"Primary","score":"7.6","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N","baseScore":7.6,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"}},{"version":"3.1","source":"psirt@us.ibm.com","type":"Secondary","score":"6.4","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"6.4","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.4,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","version":"3.1"}}],"references":[{"url":"https://www.ibm.com/support/pages/node/7272628","name":"https://www.ibm.com/support/pages/node/7272628","refsource":"psirt@us.ibm.com","tags":["Vendor Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-36126","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-36126","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"IBM","product":"Cognos Analytics","version":"affected 11.2.0","platforms":[]},{"source":"CNA","vendor":"IBM","product":"Cognos Analytics","version":"affected 12.0","platforms":[]},{"source":"CNA","vendor":"IBM","product":"Cognos Analytics","version":"affected 12.1.0","platforms":[]},{"source":"CNA","vendor":"IBM","product":"Cognos Transformer","version":"affected 12.0","platforms":[]},{"source":"CNA","vendor":"IBM","product":"Cognos Transformer","version":"affected 11.2.4","platforms":[]},{"source":"CNA","vendor":"IBM","product":"Cognos Transformer","version":"affected 12.1.0","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"IBM strongly recommends addressing the vulnerability now by upgrading to latest versions\n\nProduct(s)Version(s) number and/or range Remediation/Fix/InstructionsIBM Cognos Analytics11.2.0 - 11.2.4 FP6 IBM Cognos Analytics 11.2.4 Fix Pack 7 https://www.ibm.com/support/pages/node/7270262 IBM Cognos Analytics12.0.0 - 12.0.4 FP1 IBM Cognos Analytics 12.0.4 Fix Pack 2 https://www.ibm.com/support/pages/node/7269268 IBM Cognos Analytics12.1.0 - 12.1.1 IF1 IBM Cognos Analytics 12.1.2 https://www.ibm.com/support/pages/node/7258071","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2025","cve_id":"36126","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"cognos_analytics","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2025","cve_id":"36126","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"cognos_analytics","cpe6":"11.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2025","cve_id":"36126","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"cognos_analytics","cpe6":"11.2.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2025","cve_id":"36126","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"cognos_analytics","cpe6":"11.2.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2025","cve_id":"36126","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"cognos_analytics","cpe6":"11.2.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2025","cve_id":"36126","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"cognos_analytics","cpe6":"11.2.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2025","cve_id":"36126","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"cognos_analytics","cpe6":"11.2.4","cpe7":"-","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2025","cve_id":"36126","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"cognos_analytics","cpe6":"11.2.4","cpe7":"fixpack1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2025","cve_id":"36126","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"cognos_analytics","cpe6":"11.2.4","cpe7":"fixpack2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2025","cve_id":"36126","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"cognos_analytics","cpe6":"11.2.4","cpe7":"fixpack3","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2025","cve_id":"36126","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"cognos_analytics","cpe6":"11.2.4","cpe7":"fixpack4","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2025","cve_id":"36126","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"cognos_analytics","cpe6":"11.2.4","cpe7":"fixpack5","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2025","cve_id":"36126","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"cognos_analytics","cpe6":"11.2.4","cpe7":"fixpack6","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2025","cve_id":"36126","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"cognos_analytics","cpe6":"11.2.4","cpe7":"interim_fix_1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2025","cve_id":"36126","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"cognos_analytics","cpe6":"11.2.4","cpe7":"interim_fix_2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2025","cve_id":"36126","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"cognos_analytics","cpe6":"11.2.4","cpe7":"interim_fix_3","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2025","cve_id":"36126","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"cognos_analytics","cpe6":"11.2.4","cpe7":"interim_fix_4","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2025","cve_id":"36126","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"cognos_analytics","cpe6":"11.2.4","cpe7":"interim_fix_5","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2025","cve_id":"36126","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"cognos_analytics","cpe6":"12.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2025","cve_id":"36126","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"cognos_analytics","cpe6":"12.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2025","cve_id":"36126","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"cognos_analytics","cpe6":"12.0.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2025","cve_id":"36126","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"cognos_analytics","cpe6":"12.0.3","cpe7":"-","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2025","cve_id":"36126","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"cognos_analytics","cpe6":"12.0.3","cpe7":"interim_fix_1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2025","cve_id":"36126","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"cognos_analytics","cpe6":"12.0.3","cpe7":"interim_fix_2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2025","cve_id":"36126","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"cognos_analytics","cpe6":"12.0.4","cpe7":"-","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2025","cve_id":"36126","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"cognos_analytics","cpe6":"12.0.4","cpe7":"fixpack1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2025","cve_id":"36126","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"cognos_analytics","cpe6":"12.0.4","cpe7":"interim_fix_1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2025","cve_id":"36126","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"cognos_analytics","cpe6":"12.0.4","cpe7":"interim_fix_2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2025","cve_id":"36126","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"cognos_analytics","cpe6":"12.0.4","cpe7":"interim_fix_3","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2025","cve_id":"36126","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"cognos_transformer","cpe6":"11.2.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2025","cve_id":"36126","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"cognos_transformer","cpe6":"12.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2025","cve_id":"36126","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"cognos_transformer","cpe6":"12.1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2025","cve_id":"36126","cve":"CVE-2025-36126","epss":"0.000290000","percentile":"0.087860000","score_date":"2026-06-03","updated_at":"2026-06-04 00:06:35"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2025-36126","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-05-27T17:20:04.656302Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-05-27T17:20:14.707Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"cpes":["cpe:2.3:a:ibm:cognos_analytics:11.2.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:cognos_analytics:12.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:cognos_analytics:12.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:cognos_analytics:12.1.0:*:*:*:*:*:*:*"],"product":"Cognos Analytics","vendor":"IBM","versions":[{"status":"affected","version":"11.2.0"},{"status":"affected","version":"12.0"},{"status":"affected","version":"12.1.0"}]},{"cpes":["cpe:2.3:a:ibm:cognos_transformer:12.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:cognos_transformer:12.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:cognos_transformer:11.2.4:*:*:*:*:*:*:*","cpe:2.3:a:ibm:cognos_transformer:12.1.0:*:*:*:*:*:*:*"],"product":"Cognos Transformer","vendor":"IBM","versions":[{"status":"affected","version":"12.0"},{"status":"affected","version":"11.2.4"},{"status":"affected","version":"12.1.0"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>IBM Cognos Analytics 11.2.0, 12.0, and 12.1.0 and IBM Cognos Transformer 12.0, 11.2.4, and 12.1.0 is vulnerable to stored cross-site scripting (XSS) in Cognos Adminstration. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.</p>"}],"value":"IBM Cognos Analytics 11.2.0, 12.0, and 12.1.0 and IBM Cognos Transformer 12.0, 11.2.4, and 12.1.0 is vulnerable to stored cross-site scripting (XSS) in Cognos Adminstration. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.4,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-79","description":"CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-05-27T12:05:00.708Z","orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm"},"references":[{"tags":["vendor-advisory","patch"],"url":"https://www.ibm.com/support/pages/node/7272628"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>IBM strongly recommends addressing the vulnerability now by upgrading to latest versions</p><div><table><tbody><tr><td><strong>Product(s)</strong></td><td><strong>Version(s) number and/or range </strong></td><td><strong>Remediation/Fix/Instructions</strong></td></tr><tr><td>IBM Cognos Analytics</td><td>11.2.0 - 11.2.4 FP6</td><td><a href=\"https://www.ibm.com/support/pages/node/7270262\" rel=\"noopener noreferrer nofollow\">IBM Cognos Analytics 11.2.4 Fix Pack 7</a></td></tr><tr><td>IBM Cognos Analytics</td><td>12.0.0 - 12.0.4 FP1</td><td><a href=\"https://www.ibm.com/support/pages/node/7269268\" rel=\"noopener noreferrer nofollow\">IBM Cognos Analytics 12.0.4 Fix Pack 2</a></td></tr><tr><td>IBM Cognos Analytics</td><td>12.1.0 - 12.1.1 IF1</td><td><a href=\"https://www.ibm.com/support/pages/node/7258071\" rel=\"noopener noreferrer nofollow\">IBM Cognos Analytics 12.1.2</a></td></tr></tbody></table></div><p></p>"}],"value":"IBM strongly recommends addressing the vulnerability now by upgrading to latest versions\n\nProduct(s)Version(s) number and/or range Remediation/Fix/InstructionsIBM Cognos Analytics11.2.0 - 11.2.4 FP6 IBM Cognos Analytics 11.2.4 Fix Pack 7 https://www.ibm.com/support/pages/node/7270262 IBM Cognos Analytics12.0.0 - 12.0.4 FP1 IBM Cognos Analytics 12.0.4 Fix Pack 2 https://www.ibm.com/support/pages/node/7269268 IBM Cognos Analytics12.1.0 - 12.1.1 IF1 IBM Cognos Analytics 12.1.2 https://www.ibm.com/support/pages/node/7258071"}],"title":"IBM Cognos Analytics is affected by Cross-site scripting.","x_generator":{"engine":"ibm-cvegen"}}},"cveMetadata":{"assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","assignerShortName":"ibm","cveId":"CVE-2025-36126","datePublished":"2026-05-26T15:52:49.002Z","dateReserved":"2025-04-15T21:16:18.171Z","dateUpdated":"2026-05-27T17:20:14.707Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-05-26 17:16:28","lastModifiedDate":"2026-06-01 17:30:40","problem_types":["CWE-79","CWE-79 CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N","baseScore":7.6,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":4.7}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:*:*:*:*:*:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.2","matchCriteriaId":"30BF0C71-FEDA-4D86-BE94-54D67AA482BA"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:11.2:*:*:*:*:*:*:*","matchCriteriaId":"348B7AB4-F304-461B-AC45-D8656AB73660"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:11.2.0:*:*:*:*:*:*:*","matchCriteriaId":"1AB1B390-838B-4572-ACA0-2CFFDDB45EB1"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:11.2.1:*:*:*:*:*:*:*","matchCriteriaId":"D500E11C-4A99-460F-B16A-4DA5895149D5"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:11.2.2:*:*:*:*:*:*:*","matchCriteriaId":"BC703EBB-A37C-465C-8F7C-3B64AB3A71E4"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:11.2.3:*:*:*:*:*:*:*","matchCriteriaId":"8CA6708A-851A-458C-81CC-0AE78CB0F0C0"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:11.2.4:-:*:*:*:*:*:*","matchCriteriaId":"A1D81212-AFFE-4A73-AAC1-E558973FC452"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:11.2.4:fixpack1:*:*:*:*:*:*","matchCriteriaId":"07DC144D-62FC-4808-A77A-642871C1F8FC"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:11.2.4:fixpack2:*:*:*:*:*:*","matchCriteriaId":"2A61B920-B490-48A8-BF00-13B8854683FD"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:11.2.4:fixpack3:*:*:*:*:*:*","matchCriteriaId":"1F65BC6D-9A9D-45B9-919B-2855586C4F1B"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:11.2.4:fixpack4:*:*:*:*:*:*","matchCriteriaId":"684FA3C7-ABEA-4CB8-8D88-4BA18F1A73FB"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:11.2.4:fixpack5:*:*:*:*:*:*","matchCriteriaId":"3372238E-BFA8-4342-A523-9DB9628D11B7"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:11.2.4:fixpack6:*:*:*:*:*:*","matchCriteriaId":"0644AF6B-BBEB-4B56-A6A6-D6BE073DA900"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:11.2.4:interim_fix_1:*:*:*:*:*:*","matchCriteriaId":"C0259B4F-E86A-44E5-A1FA-39A57E915822"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:11.2.4:interim_fix_2:*:*:*:*:*:*","matchCriteriaId":"CEF69734-E894-49E2-9295-03330FE19F9C"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:11.2.4:interim_fix_3:*:*:*:*:*:*","matchCriteriaId":"28C2275C-A326-4914-BD31-923E0976DA5B"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:11.2.4:interim_fix_4:*:*:*:*:*:*","matchCriteriaId":"C19D8CDA-E883-4F76-ACEE-FE16A6AB75A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:11.2.4:interim_fix_5:*:*:*:*:*:*","matchCriteriaId":"AF2CD238-A72E-4689-B8E7-2949A0E618E2"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:12.0.0:*:*:*:*:*:*:*","matchCriteriaId":"210893AF-E67A-49C1-80FC-59A1F1C1B32F"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:12.0.1:*:*:*:*:*:*:*","matchCriteriaId":"CFDD4A63-2F81-48C8-8400-E1BE15C8EA3D"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:12.0.2:*:*:*:*:*:*:*","matchCriteriaId":"0AF83D3E-FB2F-4A73-A18B-F55CB98124D6"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:12.0.3:-:*:*:*:*:*:*","matchCriteriaId":"42EB9F80-DCF1-474F-A5A5-7BC9F0B3BF58"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:12.0.3:interim_fix_1:*:*:*:*:*:*","matchCriteriaId":"706340D8-0E0B-4775-B90A-E696CFFB9901"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:12.0.3:interim_fix_2:*:*:*:*:*:*","matchCriteriaId":"651FEB1B-83C8-4D28-8944-E8C182AC93B6"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:12.0.4:-:*:*:*:*:*:*","matchCriteriaId":"CED100CC-0C88-41B9-8742-4AD51C105527"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:12.0.4:fixpack1:*:*:*:*:*:*","matchCriteriaId":"206ABB8E-0FEB-4366-B547-514A3FF8138E"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:12.0.4:interim_fix_1:*:*:*:*:*:*","matchCriteriaId":"3C54FA39-7D14-434E-A9FB-5606A3A08185"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:12.0.4:interim_fix_2:*:*:*:*:*:*","matchCriteriaId":"BAB2758C-ECD5-4186-823A-5DB55265BC55"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:12.0.4:interim_fix_3:*:*:*:*:*:*","matchCriteriaId":"60BC347B-50AB-440E-A2C0-904DC9704581"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_transformer:11.2.4:*:*:*:*:*:*:*","matchCriteriaId":"9FF70630-4FCC-42CB-AEC0-0341335E38CC"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_transformer:12.0:*:*:*:*:*:*:*","matchCriteriaId":"91020D54-7072-4B79-AC60-DD68E8F36C7F"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_transformer:12.1.0:*:*:*:*:*:*:*","matchCriteriaId":"E1B1D10C-E219-4536-89AB-F7B6A16B0A97"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2025","CveId":"36126","Ordinal":"1","Title":"IBM Cognos Analytics is affected by Cross-site scripting.","CVE":"CVE-2025-36126","Year":"2025"},"notes":[{"CveYear":"2025","CveId":"36126","Ordinal":"1","NoteData":"IBM Cognos Analytics 11.2.0, 12.0, and 12.1.0 and IBM Cognos Transformer 12.0, 11.2.4, and 12.1.0 is vulnerable to stored cross-site scripting (XSS) in Cognos Adminstration. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.","Type":"Description","Title":"IBM Cognos Analytics is affected by Cross-site scripting."}]}}}