CVE-2025-3633 PUBLISHED

IBM Cognos Analytics is affected by multiple security vulnerabilities

Assigner: ibm
Reserved: 15.04.2025 Published: 27.05.2026 Updated: 27.05.2026

IBM Cognos Analytics 11.2.0, 11.2.4, 12.0, and 12.1.0 and IBM Cognos Transformer 11.2.4, 12.0, and 12.1.0 are vulnerable to cross-site scripting (XSS). This vulnerability allows a remote attacker to inject arbitrary JavaScript code into the web user interface, which may alter the intended functionality and could lead to the disclosure of credentials within a trusted session.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS Score: 5.4

Product Status

Vendor IBM
Product Cognos Analytics
Versions
  • Version 11.2.0 is affected
  • Version 12.0 is affected
  • Version 12.1.0 is affected
Vendor IBM
Product Cognos Transformer
Versions
  • Version 12.0 is affected
  • Version 11.2.4 is affected
  • Version 12.1.0 is affected

Solutions

IBM strongly recommends addressing the vulnerability now by upgrading to latest versionsProduct(s)Version(s) number and/or range Remediation/Fix/InstructionsIBM Cognos Analytics11.2.0 - 11.2.4 FP6IBM Cognos Analytics 11.2.4 Fix Pack 7IBM Cognos Analytics12.0.0 - 12.0.4 FP1IBM Cognos Analytics 12.0.4 Fix Pack 2IBM Cognos Analytics12.1.0 - 12.1.1 IF1IBM Cognos Analytics 12.1.2

References

Problem Types

  • CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE