First published: Fri Dec 03 2021(Updated: )
IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 197794.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Analytics | >=11.1.0<11.1.7 | |
IBM Cognos Analytics | =11.1.7 | |
IBM Cognos Analytics | =11.1.7-fixpack1 | |
IBM Cognos Analytics | =11.1.7-fixpack2 | |
IBM Cognos Analytics | =11.1.7-fixpack3 | |
IBM Cognos Analytics | =11.2.0 | |
NetApp OnCommand Insight |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
IBM Cognos Analytics is a business intelligence and analytics software platform.
Cross-site scripting (XSS) is a type of security vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.
The cross-site scripting vulnerability in IBM Cognos Analytics allows users to embed arbitrary JavaScript code in the web UI, potentially leading to credentials disclosure within a trusted session.
The severity of the IBM Cognos Analytics cross-site scripting vulnerability is medium with a severity score of 6.1.
To mitigate the cross-site scripting vulnerability in IBM Cognos Analytics, it is recommended to apply the latest security patches or updates provided by IBM.