QID 378917

Date Published: 2023-10-09

QID 378917: IBM Cognos Analytics Multiple Vulnerabilities (7040744)

IBM Cognos Analytics offers guided, self-service capabilities designed to solve problems and seize new opportunities quickly.

Multiple CVEs that could steal sensitive information or execute arbitrary code on the target.

Affected Versions:
IBM Cognos Analytics 11.1
IBM Cognos Analytics 11.2
IBM Cognos Analytics 12.0

QID Detection Logic (Authenticated):
This QID checks for vulnerable version of IBM Cognos Analytics by checking the registry file.

An attacker could exploit these vulnerability to execute arbitrary code on the system.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 8.3 severity.
  • Solution
    Vendor has released fix to this vulnerability. Further information can be obtained from IBM
    Vendor References

    CVEs related to QID 378917

    Software Advisories
    Advisory ID Software Component Link
    7040744 URL Logo www.ibm.com/support/pages/node/7040744