Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
120 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.2) | 0.24% | — | IBM Cognos Analytics | 18/12/2024 | 17/6/2026 | IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user… | |
| Analizada | Media (6.1) | 0.28% | — | IBM Cognos Analytics | 18/12/2024 | 17/6/2026 | IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. | |
| Analizada | Media (6.1) | 0.28% | — | IBM Cognos Analytics | 18/12/2024 | 17/6/2026 | IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 is potentially vulnerable to Cross Site Scripting (XSS). A remote attacker could execute malicious commands due to improper validation of column headings in Cognos Explorations. | |
| Analizada | Media (5.5) | 0.14% | — | IBM Cognos AnalyticsIBM Cognos Analytics Reports | 22/9/2024 | 17/6/2026 | IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and IBM Cognos Analytics Reports for iOS 11.0.0.7 could allow a local attacker to obtain sensitive information in the form of an API key. An attacker could use this information to launch further attacks against affected… | |
| Modificada | Media (5.9) | 0.28% | — | IBM Cognos Analytics | 28/6/2024 | 17/6/2026 | IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, and 12.0.2 is vulnerable to improper certificate validation when using the IBM Planning Analytics Data Source Connection. This could allow an attacker to spoof a trusted entity by interfering in the communication path between IBM Planning… | |
| Modificada | Media (5.4) | 0.38% | — | IBM Cognos Analytics | 28/6/2024 | 17/6/2026 | IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, and 12.0.2 is potentially vulnerable to cross site scripting (XSS). A remote attacker could execute malicious commands due to improper validation of column headings in Cognos Assistant. IBM X-Force ID: 282780. | |
| Analizada | Alta (8.6) | 0.64% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 2/5/2024 | 17/6/2026 | IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.2 is vulnerable to injection attacks in application logging by not sanitizing user provided data. This could lead to further attacks against the system. IBM X-Force ID: 282956. | |
| Analizada | Media (5.4) | 0.63% | — | Netapp Oncommand InsightIBM Cognos Analytics | 26/2/2024 | 17/6/2026 | IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 267451. | |
| Analizada | Media (6.1) | 0.69% | — | Netapp Oncommand InsightIBM Cognos Analytics | 26/2/2024 | 17/6/2026 | IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 260744. | |
| Analizada | Media (4.3) | 0.38% | — | Netapp Oncommand InsightIBM Cognos Analytics | 26/2/2024 | 17/6/2026 | IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 is vulnerable to form action hijacking where it is possible to modify the form action to reference an arbitrary path. IBM X-Force ID: 255898. | |
| Analizada | Media (5.3) | 0.42% | — | Netapp Oncommand InsightIBM Cognos Analytics | 26/2/2024 | 17/6/2026 | IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 could be vulnerable to information leakage due to unverified sources in messages sent between Windows objects of different origins. IBM X-Force ID: 254290. | |
| Analizada | Media (6.5) | 1.2% | — | Netapp Oncommand InsightIBM Cognos Analytics | 26/2/2024 | 17/6/2026 | IBM Cognos Analytics Mobile Server 11.1.7, 11.2.4, and 12.0.0 is vulnerable to Denial of Service due to due to weak or absence of rate limiting. By making unlimited http requests, it is possible for a single user to exhaust server resources over a period of time making service unavailable for other legitimate users.… | |
| Modificada | Media (5.4) | 0.46% | — | IBM Cognos Analytics | 16/8/2023 | 17/6/2026 | IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 257705. | |
| Modificada | Media (5.3) | 1.0% | — | IBM Cognos Analytics | 16/8/2023 | 17/6/2026 | IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a remote attacker to obtain system information without authentication which could be used in reconnaissance to gather information that could be used for future attacks. IBM X-Force ID: 257703. | |
| Modificada | Media (5.4) | 0.68% | — | IBM Cognos Analytics | 22/7/2023 | 17/6/2026 | IBM Cognos Analytics 11.1 and 11.2 is vulnerable to stored cross-site scripting, caused by improper validation of SVG Files in Custom Visualizations. A remote attacker could exploit this vulnerability to execute scripts in a victim's Web browser within the security context of the hosting Web site. An attacker could… | |
| Modificada | Media (5.4) | 0.49% | — | IBM Cognos Analytics | 22/7/2023 | 17/6/2026 | IBM Cognos Analytics 11.1 and 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 247861. | |
| Modificada | Media (4.3) | 0.72% | — | Cognos Analytics Cartridge FOR IBM Cloud PAK FOR Data | 10/7/2023 | 17/6/2026 | IBM Cognos Analytics on Cloud Pak for Data 4.0 could allow an attacker to make system calls that might compromise the security of the containers due to misconfigured security context. IBM X-Force ID: 251465. | |
| Modificada | Media (6.1) | 0.53% | — | IBM Cognos Analytics | 12/5/2023 | 17/6/2026 | IBM Cognos Analytics 11.1 and 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 213966. | |
| Modificada | Media (5.3) | 0.54% | — | IBM Cognos Analytics | 19/12/2022 | 17/6/2026 | IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could be vulnerable to sensitive information exposure by passing API keys to log files. If these keys contain sensitive information, it could lead to further attacks. IBM X-Force ID: 240450. | |
| Modificada | Alta (7.5) | 0.60% | — | IBM Cognos Analytics | 19/12/2022 | 17/6/2026 | IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could be vulnerable to a Log Injection attack by constructing URLs from user-controlled data. This could enable attackers to make arbitrary requests to the internal network or to the local file system. IBM X-Force ID: 240266. | |
| Modificada | Media (6.1) | 0.40% | — | IBM Cognos Analytics | 19/12/2022 | 17/6/2026 | IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 235064. | |
| Modificada | Crítica (9.1) | 0.44% | — | IBM Cognos Analytics | 19/12/2022 | 17/6/2026 | IBM Cognos Analytics 11.1.7 11.2.0, and 11.2.1 could be vulnerable to a Server-Side Request Forgery Attack (SSRF) attack by constructing URLs from user-controlled data. This could enable attackers to make arbitrary requests to the internal network or to the local file system. IBM X-Force ID: 234180. | |
| Modificada | Media (6.5) | 0.42% | — | IBM Cognos Analytics | 3/11/2022 | 17/6/2026 | "IBM Cognos Analytics 11.2.1, 11.2.0, 11.1.7 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 229963." | |
| Modificada | Alta (8.1) | 1.9% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 1/9/2022 | 17/6/2026 | IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 233571. | |
| Modificada | Alta (7.5) | 1.7% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 1/9/2022 | 17/6/2026 | IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to a denial of service via email flooding caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume all available CPU resources. IBM X-Force ID: 227591. |