First published: Thu Feb 27 2025(Updated: )
IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 and 12.0.0 through 12.0.4 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Analytics | <=12.0.0-12.0.4 | |
IBM Cognos Analytics | <=11.2.0-11.2.4 FP5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-0823 is a high-severity vulnerability that allows unauthorized directory traversal in IBM Cognos Analytics.
To remediate CVE-2025-0823, apply the relevant patches provided by IBM for Cognos Analytics versions 11.2.0 through 11.2.4 FP5 and 12.0.0 through 12.0.4.
IBM Cognos Analytics versions 11.2.0 through 11.2.4 FP5 and 12.0.0 through 12.0.4 are vulnerable to CVE-2025-0823.
CVE-2025-0823 can be exploited through a remote directory traversal attack using crafted URL requests with 'dot dot' sequences.
If your organization is using a vulnerable version of IBM Cognos Analytics, you should immediately apply the security patches and consult IBM's support documentation for additional guidance.