CVE-2025-33147: IBM Cognos Analytics versions 12.0.4 and 12.1.3 is affected by security vulnerabilities
IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 could allow an attacker on a shared network to obtain sensitive information caused by insecure network communication.
Other sources
IBM Cognos Analytics Certified Containers could allow an attacker on a shared network to obtain sensitive information caused by insecure network communication.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Cognos Analyticsto a version that resolves this vulnerability.Fixed in 12.0.4 FP3 - Upgrade
Upgrade
IBM Cognos Analyticsto a version that resolves this vulnerability.Fixed in 12.1.3 FP2
Event History
Frequently Asked Questions
Who is exposed to this issue?
Deployments of IBM Cognos Analytics Certified Containers are exposed when an attacker can access the same shared network and observe insecure network communications.
What does an attacker need to exploit this vulnerability?
The attacker needs a position on a shared network with the affected deployment. The disclosed impact is the ability to obtain sensitive information from insecure network communication.