CVE-2025-33123: IBM Cognos Analytics vulnerability
Published Sep 11, 2026
·Updated
IBM Cognos Analytics is vulnerable to an email injection vulnerability. A remote attacker could exploit this vulnerability to manipulate email content and recipients which can be further exploited in further attacks.
Affected Software
2 affected components
IBM Cognos Analytics<=12.1.0 - 12.1.3 FP1
IBM Cognos Analytics<=12.0.4 - 12.0.4 FP2
Event History
Sep 11, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
Does the provided record identify affected IBM Cognos Analytics versions, fixed releases, or temporary mitigations?
No. The provided data does not specify affected versions, a fixed version, configuration workarounds, or other mitigations.