CVE-2025-33147 PUBLISHED

IBM Cognos Analytics versions 12.0.4 and 12.1.3 is affected by security vulnerabilities

Assigner: ibm
Reserved: 15.04.2025 Published: 18.09.2026 Updated: 18.09.2026

IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 could allow an attacker on a shared network to obtain sensitive information caused by insecure network communication.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS Score: 5.9

Product Status

Vendor IBM
Product Cognos Analytics
Versions
  • affected from 12.1.0 to 12.1.3 FP1 (incl.)
  • affected from 12.0.4 to 12.0.4 FP2 (incl.)

Solutions

IBM strongly recommends addressing the vulnerability now.

Affected Product(s)Version(s)Fix VersionIBM Cognos Analytics12.1.0, 12.1.1, 12.1.2, 12.1.3, 12.1.3 FP1 12.1.3 FP2 https://www.ibm.com/support/pages/node/7283969 IBM Cognos Analytics12.0.4 - 12.0.4 FP2 12.0.4 FP3 https://www.ibm.com/support/pages/node/7269268

References

Problem Types

  • CWE-327 Use of a Broken or Risky Cryptographic Algorithm CWE