QID 376090

Date Published: 2021-12-09

QID 376090: IBM Cognos Analytics Multiple Vulnerabilities (6491661)

IBM Cognos Analytics offers guided, self-service capabilities designed to solve problems and seize new opportunities quickly.

Affected Versions:
IBM Cognos Analytics 11.2.0
IBM Cognos Analytics 11.1.7 to 11.1.7 FP2

QID Detection Logic (Authenticated):
This QID checks for vulnerable version of IBM Cognos Analytics by checking the cmplst.txt file.

An attacker could exploit these vulnerability to obtain sensitive information and execute arbitrary code on the system.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Vendor has released fix to this vulnerability. Further information can be obtained from IBM
    Download link for :
    Cognos Analytics 11.1.7 Fix Pack 3 Cognos Analytics 11.2.1
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    6491661 URL Logo www.ibm.com/support/pages/node/6491661