QID 379452

Date Published: 2024-03-07

QID 379452: IBM Cognos Analytics Multiple Vulnerabilities (7123154)

IBM Cognos Analytics offers guided, self-service capabilities designed to solve problems and seize new opportunities quickly.

Multiple CVEs that could steal sensitive information or execute arbitrary code on the target.

Affected Versions:
IBM Cognos Analytics 11.1.1-11.1.7 FP7
IBM Cognos Analytics 11.2.0-11.2.4 FP2
IBM Cognos Analytics 12.0.0-12.0.1

QID Detection Logic (Authenticated):
This QID checks for vulnerable version of IBM Cognos Analytics by checking the registry file.

An attacker could exploit these vulnerability to execute arbitrary code on the system.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Vendor has released fix to this vulnerability. Further information can be obtained from IBM Cognos Analytics
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    7123154 URL Logo www.ibm.com/support/pages/node/7123154