QID 376056

Date Published: 2022-01-03

QID 376056: IBM Cognos Analytics Multiple Vulnerabilities (566643)

IBM Cognos Analytics offers guided, self-service capabilities designed to solve problems and seize new opportunities quickly.

Affected Versions:
IBM Cognos Analytics Version 11.0.0.0 to 11.0.6.0

QID Detection Logic (Authenticated):
This QID checks for vulnerable versions of IBM Cognos Analytics by checking the registry file.

An attacker could exploit these vulnerabilities to execute arbitrary code on the system, denial of service attacks, cross-site scripting, obtain sensitive information.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 9.3 severity.
  • Solution
    Vendor has released fix to this vulnerability in IBM Cognos Analyticds 11.0.7.0. Further information can be obtained from swg22007242
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    swg22007242 URL Logo www.ibm.com/support/docview.wss?uid=swg22007242