Back

HIGH

IBM Cognos Anaytics XML external entity injection

Published Feb 5, 2025

Description

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner ibm
Published Feb 5, 2025
Updated Feb 22, 2025
Reserved Oct 14, 2024

CISA Vulnrichment

Updated Feb 5, 2025

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner ibm
Published Feb 5, 2025
Updated Feb 22, 2025

GitHub

No data