Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
120 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 2.0% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 15/10/2021 | 17/6/2026 | IBM Cognos Analytics 11.1.7 and 11.2.0 could allow an authenticated user to execute code remotely due to incorrectly neutralizaing user-contrlled input that could be interpreted a a server-side include (SSI) directive. IBM X-Force ID: 199915. | |
| Modificada | Baja (3.3) | 0.27% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 15/10/2021 | 17/6/2026 | IBM Cognos Analytics 11.1.7 and 11.2.0 contains locally cached browser data, that could allow a local attacker to obtain sensitive information. | |
| Modificada | Media (6.5) | 0.95% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 30/6/2021 | 17/6/2026 | IBM Cognos Analytics 10.0 and 11.1 is susceptible to a weakness in the implementation of the System Appearance configuration setting. An attacker could potentially bypass business logic to modify the appearance and behavior of the application. IBM X-Force ID: 196770. | |
| Modificada | Crítica (10) | 2.9% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 1/6/2021 | 17/6/2026 | IBM Cognos Analytics 11.0 and 11.1 DQM API allows submitting of all control requests in unauthenticated sessions. This allows a remote attacker who can access a valid CA endpoint to read and write files to the Cognos Analytics system. IBM X-Force ID: 183903. | |
| Modificada | Alta (8.8) | 2.7% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 1/6/2021 | 17/6/2026 | IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to inject malicious HTML code that when viewed by the authenticated victim would execute the code. IBM X-Force ID: 182395. | |
| Modificada | Media (5.4) | 0.96% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 1/6/2021 | 17/6/2026 | IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 178506. | |
| Modificada | Alta (8.2) | 4.0% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 1/6/2021 | 17/6/2026 | IBM Cognos Analytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 176607. | |
| Modificada | Alta (7.1) | 2.0% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 1/6/2021 | 17/6/2026 | IBM Cognos Analytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 172533. | |
| Modificada | Alta (7.5) | 2.4% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 1/6/2021 | 17/6/2026 | IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain credentials from a user's browser via incorrect autocomplete settings in New Content Backup page. IBM X-Force ID: 172130. | |
| Modificada | Alta (7.5) | 2.4% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 1/6/2021 | 17/6/2026 | IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain credentials from a user's browser via incorrect autocomplete settings in New Data Server Connection page. IBM X-Force ID: 172129. | |
| Modificada | Media (4.3) | 1.4% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 1/6/2021 | 17/6/2026 | IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain sensitive information via a stack trace due to mishandling of certain error conditions. IBM X-Force ID: 172128. | |
| Modificada | Media (5.4) | 0.76% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 1/6/2021 | 17/6/2026 | IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 170964. | |
| Modificada | Media (6.5) | 1.0% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 1/6/2021 | 17/6/2026 | IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain sensitive information, caused by the failure to set the secure flag for a sensitive cookie in an HTTPS session. A remote attacker could exploit this vulnerability to obtain sensitive information. IBM X-Force ID: 163780. | |
| Modificada | Alta (8.2) | 1.3% | — | IBM Cognos Analytics | 12/10/2020 | 17/6/2026 | IBM Cognos Analytics 11.0 and 11.1 could be vulnerable to a denial of service attack by failing to catch exceptions in a servlet also exposing debug information could also be used in future attacks. IBM X-Force ID: 179270. | |
| Modificada | Alta (7.8) | 1.7% | — | IBM Cognos Analytics | 12/10/2020 | 17/6/2026 | IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to execute arbitrary code on the system, caused by a CSV injection. By persuading a victim to open a specially-crafted excel file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 176610. | |
| Modificada | Crítica (9.1) | 2.1% | — | IBM Cognos Analytics | 3/8/2020 | 17/6/2026 | IBM Cognos Anaytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 179156. | |
| Modificada | Media (4.3) | 0.66% | — | IBM Cognos Analytics | 3/8/2020 | 17/6/2026 | IBM Cognos Analytics 11.0 and 11.1 is vulnerable to privlege escalation where the "My schedules and subscriptions" page is visible and accessible to a less privileged user. IBM X-Force ID: 167449. | |
| Modificada | Media (5.3) | 0.72% | — | IBM Cognos Analytics | 3/8/2020 | 17/6/2026 | IBM Cognos Analytics 11.0 and 11.1 is susceptible to an information disclosure vulnerability where an attacker could gain access to cached browser data. IBM X-Force ID: 161748. | |
| Modificada | Media (4.3) | 1.6% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 27/4/2020 | 17/6/2026 | IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 172519. | |
| Modificada | Media (5.4) | 0.67% | — | IBM Cognos Analytics | 30/12/2019 | 17/6/2026 | IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 168924. | |
| Modificada | Media (6.5) | 1.5% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 30/12/2019 | 17/6/2026 | IBM Cognos Analytics 11.0 and 11.1 allows overly permissive cross-origin resource sharing which could allow an attacker to transfer private information. An attacker could exploit this vulnerability to access content that should be restricted. IBM X-Force ID: 161422. | |
| Modificada | Media (5.4) | 0.77% | — | IBM Cognos Analytics | 20/12/2019 | 17/6/2026 | IBM Cognos Analytics 11.0 and 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 166204. | |
| Modificada | Media (4.3) | 0.72% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 20/12/2019 | 17/6/2026 | IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 159356. | |
| Modificada | Media (6.1) | 0.73% | — | IBM Cognos Analytics | 9/11/2019 | 17/6/2026 | IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 170881. | |
| Modificada | Media (4.3) | 0.92% | — | IBM Cognos Analytics | 9/11/2019 | 17/6/2026 | IBM Cognos Analytics 11.0 and 11.1 could reveal sensitive information to an authenticated user that could be used in future attacks against the system. IBM X-Force ID: 161271. |