Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
120 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.8% | — | IBM Cognos Analytics | 9/11/2019 | 17/6/2026 | IBM Cognos Analytics 11.0 and 11.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or cause the web server to make HTTP requests to arbitrary domains. IBM X-Force ID: 147369. | |
| Modificada | Media (5.4) | 0.99% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 17/9/2019 | 17/6/2026 | IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 161421. | |
| Modificada | Alta (7.5) | 3.5% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 17/9/2019 | 17/6/2026 | IBM Cognos Analytics 11.0, and 11.1 is vulnerable to a denial of service attack that could allow a remote user to send specially crafted requests that would consume all available CPU and memory resources. IBM X-Force ID: 158973. | |
| Modificada | Media (5.4) | 0.98% | — | IBM Cognos Analytics | 29/5/2019 | 17/6/2026 | IBM Cognos Analytics 11.0, 11.1.0, and 11.1.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 158335. | |
| Modificada | Crítica (9.1) | 3.1% | — | IBM Cognos Analytics | 15/4/2019 | 17/6/2026 | IBM Cognos Analytics 11 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request to write or view arbitrary files on the system. IBM X-Force ID: 158919. | |
| Modificada | Baja (3.6) | 0.26% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 9/11/2018 | 17/6/2026 | IBM Cognos Analytics 11 Configuration tool, under certain circumstances, will bypass OIDC namespace signature verification on its id_token. IBM X-Force ID: 150902. | |
| Modificada | Media (5.4) | 1.1% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 7/5/2018 | 17/6/2026 | IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138819. | |
| Modificada | Media (5.3) | 1.7% | — | IBM Cognos Analytics | 22/3/2018 | 17/6/2026 | IBM Predictive Solutions Foundation (IBM Cognos Analytics 11.0) reveals sensitive information in detailed error messages that could aid an attacker in further attacks against the system. IBM X-Force ID: 119619. | |
| Modificada | Media (5.5) | 0.38% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 29/1/2018 | 17/6/2026 | IBM Cognos Analytics 11.0 could produce results in temporary files that contain highly sensitive information that can be read by a local user. IBM X-Force ID: 136858. | |
| Modificada | Media (4) | 0.46% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 29/1/2018 | 17/6/2026 | IBM Cognos Analytics 11.0 could allow a local user to change parameters set from the Cognos Analytics menus without proper authentication. IBM X-Force ID: 136857. | |
| Modificada | Alta (7.8) | 0.41% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 29/1/2018 | 17/6/2026 | IBM Cognos Analytics 11.0 could store cached credentials locally that could be obtained by a local user. IBM X-Force ID: 136824. | |
| Modificada | Media (5.4) | 0.72% | — | IBM Cognos Analytics | 29/8/2017 | 17/6/2026 | IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 130677. | |
| Modificada | Media (5.4) | 0.54% | — | IBM Cognos Analytics | 29/8/2017 | 17/6/2026 | IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128623. | |
| Modificada | Media (6.1) | 1.2% | — | IBM Cognos Analytics | 29/8/2017 | 17/6/2026 | IBM Cognos Analytics 11.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID:… | |
| Modificada | Media (6.1) | 1.00% | — | IBM Cognos Analytics | 29/8/2017 | 17/6/2026 | IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 127579. | |
| Modificada | Media (5.4) | 0.51% | — | IBM Cognos Analytics | 10/5/2017 | 17/6/2026 | IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 114516. | |
| Modificada | Media (5.4) | 0.52% | — | IBM Cognos Analytics | 5/4/2017 | 17/6/2026 | IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1998887. | |
| Modificada | Media (5.4) | 0.52% | — | IBM Cognos Analytics | 5/4/2017 | 17/6/2026 | IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1998887. | |
| Modificada | Media (5.4) | 0.70% | — | IBM Cognos Analytics | 1/2/2017 | 17/6/2026 | IBM Cognos Business Intelligence and IBM Cognos Analytics are vulnerable to stored cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim's Web browser within the… | |
| Modificada | Media (4.3) | 1.2% | — | IBM Cognos Analytics | 2/7/2016 | 17/6/2026 | IBM Cognos Analytics (CA) 11.0 before 11.0.2 allows remote attackers to conduct content-spoofing attacks via a crafted URL. |