CVE-2025-0923: IBM Cognos Analytics information disclosure
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 stores source code on the web server that could aid in further attacks against the system.
Other sources
IBM Cognos Analytics stores source code on the web server that could aid in further attacks against the system.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0923?
CVE-2025-0923 is rated as a medium severity vulnerability due to the risk of exposing source code that could facilitate further attacks.
How do I fix CVE-2025-0923?
Fixing CVE-2025-0923 involves updating IBM Cognos Analytics to a patched version where the source code exposure issue has been addressed.
What versions of IBM Cognos Analytics are affected by CVE-2025-0923?
CVE-2025-0923 affects IBM Cognos Analytics versions 11.2.0 through 11.2.4 and 12.0.0 through 12.0.4.
What kind of information is exposed by CVE-2025-0923?
CVE-2025-0923 exposes source code stored on the web server, which can be leveraged for further attacks against the system.
Is it safe to use IBM Cognos Analytics versions affected by CVE-2025-0923?
Using affected versions of IBM Cognos Analytics presents security risks, and it is recommended to upgrade to secure versions to mitigate these risks.