{"api_version":"1","generated_at":"2026-06-04T11:56:07+00:00","cve":"CVE-2025-3633","urls":{"html":"https://cve.report/CVE-2025-3633","api":"https://cve.report/api/cve/CVE-2025-3633.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2025-3633","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2025-3633"},"summary":{"title":"IBM Cognos Analytics is affected by multiple security vulnerabilities","description":"IBM Cognos Analytics 11.2.0, 11.2.4, 12.0, and 12.1.0 and IBM Cognos Transformer 11.2.4, 12.0, and 12.1.0 are vulnerable to cross-site scripting (XSS). This vulnerability allows a remote attacker to inject arbitrary JavaScript code into the web user interface, which may alter the intended functionality and could lead to the disclosure of credentials within a trusted session.","state":"PUBLISHED","assigner":"ibm","published_at":"2026-05-27 14:16:42","updated_at":"2026-06-02 20:05:07"},"problem_types":["CWE-79","CWE-79 CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"],"metrics":[{"version":"3.1","source":"nvd@nist.gov","type":"Primary","score":"8.2","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"}},{"version":"3.1","source":"psirt@us.ibm.com","type":"Secondary","score":"5.4","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"5.4","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","version":"3.1"}}],"references":[{"url":"https://www.ibm.com/support/pages/node/7272628","name":"https://www.ibm.com/support/pages/node/7272628","refsource":"psirt@us.ibm.com","tags":["Vendor Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-3633","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-3633","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"IBM","product":"Cognos Analytics","version":"affected 11.2.0","platforms":[]},{"source":"CNA","vendor":"IBM","product":"Cognos Analytics","version":"affected 12.0","platforms":[]},{"source":"CNA","vendor":"IBM","product":"Cognos Analytics","version":"affected 12.1.0","platforms":[]},{"source":"CNA","vendor":"IBM","product":"Cognos Transformer","version":"affected 12.0","platforms":[]},{"source":"CNA","vendor":"IBM","product":"Cognos Transformer","version":"affected 11.2.4","platforms":[]},{"source":"CNA","vendor":"IBM","product":"Cognos Transformer","version":"affected 12.1.0","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"IBM strongly recommends addressing the vulnerability now by upgrading to latest versionsProduct(s)Version(s) number and/or range Remediation/Fix/InstructionsIBM Cognos Analytics11.2.0 - 11.2.4 FP6IBM Cognos Analytics 11.2.4 Fix Pack 7IBM Cognos Analytics12.0.0 - 12.0.4 FP1IBM Cognos Analytics 12.0.4 Fix Pack 2IBM Cognos Analytics12.1.0 - 12.1.1 IF1IBM Cognos Analytics 12.1.2","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2025","cve_id":"3633","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"cognos_analytics","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2025","cve_id":"3633","cve":"CVE-2025-3633","epss":"0.000320000","percentile":"0.099450000","score_date":"2026-06-01","updated_at":"2026-06-02 00:05:21"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2025-3633","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-05-27T14:27:31.520327Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-05-27T14:31:40.895Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"cpes":["cpe:2.3:a:ibm:cognos_analytics:11.2.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:cognos_analytics:12.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:cognos_analytics:12.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:cognos_analytics:12.1.0:*:*:*:*:*:*:*"],"product":"Cognos Analytics","vendor":"IBM","versions":[{"status":"affected","version":"11.2.0"},{"status":"affected","version":"12.0"},{"status":"affected","version":"12.1.0"}]},{"cpes":["cpe:2.3:a:ibm:cognos_transformer:12.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:cognos_transformer:12.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:cognos_transformer:11.2.4:*:*:*:*:*:*:*","cpe:2.3:a:ibm:cognos_transformer:12.1.0:*:*:*:*:*:*:*"],"product":"Cognos Transformer","vendor":"IBM","versions":[{"status":"affected","version":"12.0"},{"status":"affected","version":"11.2.4"},{"status":"affected","version":"12.1.0"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>IBM Cognos Analytics 11.2.0, 11.2.4, 12.0, and 12.1.0 and IBM Cognos Transformer 11.2.4, 12.0, and 12.1.0 are vulnerable to cross-site scripting (XSS). This vulnerability allows a remote attacker to inject arbitrary JavaScript code into the web user interface, which may alter the intended functionality and could lead to the disclosure of credentials within a trusted session.</p>"}],"value":"IBM Cognos Analytics 11.2.0, 11.2.4, 12.0, and 12.1.0 and IBM Cognos Transformer 11.2.4, 12.0, and 12.1.0 are vulnerable to cross-site scripting (XSS). This vulnerability allows a remote attacker to inject arbitrary JavaScript code into the web user interface, which may alter the intended functionality and could lead to the disclosure of credentials within a trusted session."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-79","description":"CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-05-27T12:17:11.519Z","orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm"},"references":[{"tags":["vendor-advisory","patch"],"url":"https://www.ibm.com/support/pages/node/7272628"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>IBM strongly recommends addressing the vulnerability now by upgrading to latest versions</p><div><table><tbody><tr><td><strong>Product(s)</strong></td><td><strong>Version(s) number and/or range </strong></td><td><strong>Remediation/Fix/Instructions</strong></td></tr><tr><td>IBM Cognos Analytics</td><td>11.2.0 - 11.2.4 FP6</td><td><a href=\"https://www.ibm.com/support/pages/node/7270262\" rel=\"noopener noreferrer nofollow\">IBM Cognos Analytics 11.2.4 Fix Pack 7</a></td></tr><tr><td>IBM Cognos Analytics</td><td>12.0.0 - 12.0.4 FP1</td><td><a href=\"https://www.ibm.com/support/pages/node/7269268\" rel=\"noopener noreferrer nofollow\">IBM Cognos Analytics 12.0.4 Fix Pack 2</a></td></tr><tr><td>IBM Cognos Analytics</td><td>12.1.0 - 12.1.1 IF1</td><td><a href=\"https://www.ibm.com/support/pages/node/7258071\" rel=\"noopener noreferrer nofollow\">IBM Cognos Analytics 12.1.2</a></td></tr></tbody></table></div><p></p>"}],"value":"IBM strongly recommends addressing the vulnerability now by upgrading to latest versionsProduct(s)Version(s) number and/or range Remediation/Fix/InstructionsIBM Cognos Analytics11.2.0 - 11.2.4 FP6IBM Cognos Analytics 11.2.4 Fix Pack 7IBM Cognos Analytics12.0.0 - 12.0.4 FP1IBM Cognos Analytics 12.0.4 Fix Pack 2IBM Cognos Analytics12.1.0 - 12.1.1 IF1IBM Cognos Analytics 12.1.2"}],"title":"IBM Cognos Analytics is affected by multiple security vulnerabilities","x_generator":{"engine":"ibm-cvegen"}}},"cveMetadata":{"assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","assignerShortName":"ibm","cveId":"CVE-2025-3633","datePublished":"2026-05-27T12:17:11.519Z","dateReserved":"2025-04-15T09:48:14.783Z","dateUpdated":"2026-05-27T14:31:40.895Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-05-27 14:16:42","lastModifiedDate":"2026-06-02 20:05:07","problem_types":["CWE-79","CWE-79 CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":4.7}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:*:*:*:*:*:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"11.2.4","matchCriteriaId":"FA7F561D-2D45-4BDB-AE84-1BD057DC9930"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:*:*:*:*:*:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"12.0.4","matchCriteriaId":"90D7AA5F-889B-4FC6-AE9D-9659FCAC13FF"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:*:*:*:*:*:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.2","matchCriteriaId":"30BF0C71-FEDA-4D86-BE94-54D67AA482BA"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:11.2.4:-:*:*:*:*:*:*","matchCriteriaId":"A1D81212-AFFE-4A73-AAC1-E558973FC452"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:11.2.4:fixpack1:*:*:*:*:*:*","matchCriteriaId":"07DC144D-62FC-4808-A77A-642871C1F8FC"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:11.2.4:fixpack2:*:*:*:*:*:*","matchCriteriaId":"2A61B920-B490-48A8-BF00-13B8854683FD"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:11.2.4:fixpack3:*:*:*:*:*:*","matchCriteriaId":"1F65BC6D-9A9D-45B9-919B-2855586C4F1B"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:11.2.4:fixpack4:*:*:*:*:*:*","matchCriteriaId":"684FA3C7-ABEA-4CB8-8D88-4BA18F1A73FB"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:11.2.4:fixpack5:*:*:*:*:*:*","matchCriteriaId":"3372238E-BFA8-4342-A523-9DB9628D11B7"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:11.2.4:fixpack6:*:*:*:*:*:*","matchCriteriaId":"0644AF6B-BBEB-4B56-A6A6-D6BE073DA900"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:11.2.4:interim_fix_1:*:*:*:*:*:*","matchCriteriaId":"C0259B4F-E86A-44E5-A1FA-39A57E915822"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:11.2.4:interim_fix_2:*:*:*:*:*:*","matchCriteriaId":"CEF69734-E894-49E2-9295-03330FE19F9C"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:11.2.4:interim_fix_3:*:*:*:*:*:*","matchCriteriaId":"28C2275C-A326-4914-BD31-923E0976DA5B"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:11.2.4:interim_fix_4:*:*:*:*:*:*","matchCriteriaId":"C19D8CDA-E883-4F76-ACEE-FE16A6AB75A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:11.2.4:interim_fix_5:*:*:*:*:*:*","matchCriteriaId":"AF2CD238-A72E-4689-B8E7-2949A0E618E2"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:12.0.4:interim_fix_1:*:*:*:*:*:*","matchCriteriaId":"3C54FA39-7D14-434E-A9FB-5606A3A08185"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:12.0.4:interim_fix_2:*:*:*:*:*:*","matchCriteriaId":"BAB2758C-ECD5-4186-823A-5DB55265BC55"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:12.0.4:interim_fix_3:*:*:*:*:*:*","matchCriteriaId":"60BC347B-50AB-440E-A2C0-904DC9704581"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_transformer:11.2.4:*:*:*:*:*:*:*","matchCriteriaId":"9FF70630-4FCC-42CB-AEC0-0341335E38CC"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_transformer:12.0:*:*:*:*:*:*:*","matchCriteriaId":"91020D54-7072-4B79-AC60-DD68E8F36C7F"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_transformer:12.1.0:*:*:*:*:*:*:*","matchCriteriaId":"E1B1D10C-E219-4536-89AB-F7B6A16B0A97"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2025","CveId":"3633","Ordinal":"1","Title":"IBM Cognos Analytics is affected by multiple security vulnerabil","CVE":"CVE-2025-3633","Year":"2025"},"notes":[{"CveYear":"2025","CveId":"3633","Ordinal":"1","NoteData":"IBM Cognos Analytics 11.2.0, 11.2.4, 12.0, and 12.1.0 and IBM Cognos Transformer 11.2.4, 12.0, and 12.1.0 are vulnerable to cross-site scripting (XSS). This vulnerability allows a remote attacker to inject arbitrary JavaScript code into the web user interface, which may alter the intended functionality and could lead to the disclosure of credentials within a trusted session.","Type":"Description","Title":"IBM Cognos Analytics is affected by multiple security vulnerabil"}]}}}