CVE-2024-25042

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
18/12/2024
Last modified:
10/01/2025

Description

IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 <br /> <br /> <br /> <br /> is potentially vulnerable to Cross Site Scripting (XSS). A remote attacker could execute malicious commands due to improper validation of column headings in Cognos Explorations.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ibm:cognos_analytics:*:*:*:*:*:*:*:* 11.2.0 (including) 11.2.4 (including)
cpe:2.3:a:ibm:cognos_analytics:*:*:*:*:*:*:*:* 12.0.0 (including) 12.0.3 (including)


References to Advisories, Solutions, and Tools