CVE-2025-25032: IBM Cognos Analytics denial of service
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 could allow an authenticated user to cause a denial of service by sending a specially crafted request that would exhaust memory resources.
Other sources
IBM Cognos Analytics could allow an authenticated user to cause a denial of service by sending a specially crafted request that would exhaust memory resources.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-25032?
CVE-2025-25032 is classified as a denial of service vulnerability in IBM Cognos Analytics.
Who is affected by CVE-2025-25032?
CVE-2025-25032 affects IBM Cognos Analytics versions 11.2.0 to 11.2.4 and 12.0.0 to 12.0.4.
How do I fix CVE-2025-25032?
To mitigate CVE-2025-25032, users should update IBM Cognos Analytics to the latest version released by IBM.
What type of attack does CVE-2025-25032 allow?
CVE-2025-25032 allows an authenticated user to execute a denial of service attack by exhausting memory resources.
Can CVE-2025-25032 be exploited remotely?
CVE-2025-25032 requires an authenticated user to exploit the vulnerability, indicating it cannot be done remotely without authentication.