QID 375626

Date Published: 2021-11-30

QID 375626: IBM Cognos Analytics Multiple Vulnerabilities (6451705)

IBM Cognos Analytics offers guided, self-service capabilities designed to solve problems and seize new opportunities quickly.

Multiple CVEs that could steal sensitive information or execute arbitrary code on the target.

Affected Versions:
IBM Cognos Analytics 11.1
IBM Cognos Analytics 11.0

QID Detection Logic (Authenticated):
This QID checks for vulnerable version of IBM Cognos Analytics by checking the registry file.

An attacker could exploit these vulnerability to execute arbitrary code on the system.

  • CVSS V3 rated as Critical - 10 severity.
  • CVSS V2 rated as Critical - 8.3 severity.
  • Solution
    Vendor has released fix to this vulnerability. Further information can be obtained from IBM
    Download link for :
    Cognos Analytics 11.1.7 Fix Pack 2 Cognos Analytics 11.0.13 Fix Pack 4
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    6451705 URL Logo www.ibm.com/support/pages/node/6451705