CVE-2020-4520: XSS
IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to inject malicious HTML code that when viewed by the authenticated victim would execute the code. IBM X-Force ID: 182395.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this IBM Cognos Analytics vulnerability?
The vulnerability ID for this IBM Cognos Analytics vulnerability is CVE-2020-4520.
What is the severity of CVE-2020-4520?
The severity of CVE-2020-4520 is high with a CVSS score of 8.8.
How does CVE-2020-4520 impact IBM Cognos Analytics?
CVE-2020-4520 allows a remote attacker to inject malicious HTML code that when viewed by the authenticated victim would execute the code.
Which versions of IBM Cognos Analytics are affected by CVE-2020-4520?
IBM Cognos Analytics versions 11.0.0 and 11.1.0 are affected by CVE-2020-4520.
Are there any references available for CVE-2020-4520?
Yes, you can find more information about CVE-2020-4520 at the following references: IBM X-Force ID: 182395 (https://exchange.xforce.ibmcloud.com/vulnerabilities/182395), NetApp Advisory NTAP-20210622-0004 (https://security.netapp.com/advisory/ntap-20210622-0004/), and IBM Support Node (https://www.ibm.com/support/pages/node/6451705).