Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
120 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.21% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 1/9/2022 | 17/6/2026 | IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a local attacker to obtain information due to the autocomplete feature on password input fields. IBM X-Force ID: 214345. | |
| Modificada | Media (5.5) | 0.18% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 1/9/2022 | 17/6/2026 | IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 stores user credentials in plain clear text which can be read by a local privileged user. IBM X-Force ID: 213554. | |
| Modificada | Media (6.5) | 0.49% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 1/9/2022 | 17/6/2026 | IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 204465. | |
| Modificada | Media (6.5) | 0.41% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 1/9/2022 | 17/6/2026 | IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 196825. | |
| Modificada | Media (6.5) | 0.41% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 1/9/2022 | 17/6/2026 | IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 176609. | |
| Modificada | Media (6.1) | 0.89% | — | IBM Cognos AnalyticsIBM Planning AnalyticsNetapp Oncommand Insight | 24/6/2022 | 17/6/2026 | IBM Planning Analytics 2.0 and IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM… | |
| Modificada | Crítica (9.8) | 1.7% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 24/6/2022 | 17/6/2026 | IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 could allow a remote attacker to upload arbitrary files, caused by improper content validation. IBM X-Force ID: 211238. | |
| Modificada | Media (6.5) | 0.98% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 24/6/2022 | 17/6/2026 | IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a low level user to obtain sensitive information from the details of the 'Cloud Storage' page for which they should not have access. IBM X-Force ID: 202682. | |
| Modificada | Media (5.4) | 0.69% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 22/4/2022 | 17/6/2026 | IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 211240. | |
| Modificada | Media (4.3) | 0.92% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 22/4/2022 | 17/6/2026 | IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 could allow an authenticated user to view report pages that they should not have access to. IBM X-Force ID: 209697. | |
| Modificada | Media (6.5) | 1.8% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 22/4/2022 | 17/6/2026 | IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 could allow a remote attacker to obtain credentials from a user's browser via incorrect autocomplete settings. IBM X-Force ID: 209693. | |
| Modificada | Media (5.4) | 0.97% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 22/4/2022 | 17/6/2026 | IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim's Web browser within the security context of the… | |
| Modificada | Alta (8.8) | 0.57% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 22/4/2022 | 17/6/2026 | IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 209399. | |
| Modificada | Media (4.3) | 0.88% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 22/4/2022 | 17/6/2026 | IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to priviledge escalation where a lower level user could have read access to to the 'Data Connections' page to which they don't have access. IBM X-Force ID: 204468. | |
| Modificada | Media (6.5) | 1.4% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 22/4/2022 | 17/6/2026 | IBM Cognos Analytics PowerPlay (IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7) could be vulnerable to an XML Bomb attack by a malicious authenticated user. IBM X-Force ID: 196813. | |
| Modificada | Media (6.5) | 0.66% | — | IBM Cognos Analytics Mobile | 14/2/2022 | 17/6/2026 | Due to weak obfuscation, IBM Cognos Analytics Mobile for Android application prior to version 1.1.14 , an attacker could be able to reverse engineer the codebase to gain knowledge about the programming technique, interface, class definitions, algorithms and functions used. IBM X-Force ID: 215593. | |
| Modificada | Media (5.4) | 0.48% | — | IBM Cognos Analytics Mobile | 14/2/2022 | 17/6/2026 | IBM Cognos Analytics Mobile for Android applications prior to version 1.1.14 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM… | |
| Modificada | Media (5.4) | 0.71% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 3/12/2021 | 17/6/2026 | IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 209706. | |
| Modificada | Media (5.4) | 0.79% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 3/12/2021 | 17/6/2026 | IBM Cognos Analytics 11.1.7 and 11.2.0 could allow an authenticated to view or edit a Jupyter notebook that they should not have access to. IBM X-Force ID: 206212. | |
| Modificada | Alta (8.8) | 0.58% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 3/12/2021 | 17/6/2026 | IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site request forgery (CSRF) in the My Inbox page which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 202167. | |
| Modificada | Media (5.3) | 1.2% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 3/12/2021 | 17/6/2026 | IBM Cognos Analytics 11.1.7 and 11.2.0 could be vulnerable to client side vulnerabilties due to a web response specifying an incorrect content type. IBM X-Force ID: 201091 | |
| Modificada | Media (6.5) | 0.96% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 3/12/2021 | 17/6/2026 | IBM Cognos Analytics 11.1.7 and 11.2.0 could allow a low level user to reas of the application that privileged user should only be allowed to view. IBM X-Force ID: 201087. | |
| Modificada | Media (6.1) | 0.93% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 3/12/2021 | 17/6/2026 | IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 197794. | |
| Modificada | Alta (7.5) | 1.4% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 3/12/2021 | 17/6/2026 | IBM Cognos Analytics 11.1.7 and 11.2.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 196339. | |
| Modificada | Alta (8.8) | 1.0% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 15/10/2021 | 17/6/2026 | IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to priviledge escalation where a lower evel user could have access to the 'New Job' page to which they should not have access to. IBM X-Force ID: 201695. |