CVE-2025-0917: IBM Cognos Analytics cross-site scripting
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM Cognos Analytics is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0917?
CVE-2025-0917 is rated as a high-severity vulnerability due to its potential for stored cross-site scripting.
How does CVE-2025-0917 impact IBM Cognos Analytics?
CVE-2025-0917 allows a privileged user to inject arbitrary JavaScript into the Web UI, which can alter the application's intended functionality.
How do I fix CVE-2025-0917?
To fix CVE-2025-0917, you should update your IBM Cognos Analytics to the latest version released by IBM that addresses this vulnerability.
Who is affected by CVE-2025-0917?
CVE-2025-0917 affects IBM Cognos Analytics versions from 11.2.0 to 12.0.4.
Can CVE-2025-0917 be exploited remotely?
Yes, CVE-2025-0917 can potentially be exploited remotely by carrying out a stored cross-site scripting attack.