Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-25047


IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.2 is vulnerable to injection attacks in application logging by not sanitizing user provided data. This could lead to further attacks against the system. IBM X-Force ID: 282956.


Published

2024-05-02T21:16:11.330

Last Modified

2025-07-02T15:41:45.863

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 8.6 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-117

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ibm cognos_analytics < 11.2.4 Yes
Application ibm cognos_analytics < 12.0.3 Yes
Application ibm cognos_analytics 11.2.4 Yes
Application ibm cognos_analytics 11.2.4 Yes
Application ibm cognos_analytics 11.2.4 Yes
Application netapp oncommand_insight - Yes

References