IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
                
            Metrics
Affected Vendors & Products
References
        | Link | Providers | 
|---|---|
| https://www.ibm.com/support/pages/node/7181480 |     | 
History
                    Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | epss 
 | epss 
 | 
Wed, 02 Jul 2025 16:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Ibm Ibm cognos Analytics | |
| CPEs | cpe:2.3:a:ibm:cognos_analytics:*:*:*:*:*:*:*:* cpe:2.3:a:ibm:cognos_analytics:11.2.4:-:*:*:*:*:*:* cpe:2.3:a:ibm:cognos_analytics:11.2.4:fixpack1:*:*:*:*:*:* cpe:2.3:a:ibm:cognos_analytics:11.2.4:fixpack2:*:*:*:*:*:* cpe:2.3:a:ibm:cognos_analytics:11.2.4:fixpack3:*:*:*:*:*:* cpe:2.3:a:ibm:cognos_analytics:11.2.4:fixpack4:*:*:*:*:*:* cpe:2.3:a:ibm:cognos_analytics:12.0.4:-:*:*:*:*:*:* cpe:2.3:a:ibm:cognos_analytics:12.0.4:interim_fix_1:*:*:*:*:*:* | |
| Vendors & Products | Ibm Ibm cognos Analytics | 
Wed, 12 Feb 2025 21:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Wed, 05 Feb 2025 11:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. | |
| Title | IBM Cognos Anaytics XML external entity injection | |
| Weaknesses | CWE-611 | |
| References |  | |
| Metrics | cvssV3_1 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: ibm
Published: 2025-02-05T10:58:33.935Z
Updated: 2025-02-22T21:00:55.875Z
Reserved: 2024-10-14T12:05:24.915Z
Link: CVE-2024-49352
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-02-12T20:43:18.505Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2025-02-05T11:15:14.540
Modified: 2025-07-02T15:59:03.690
Link: CVE-2024-49352
 Redhat
                        Redhat
                    No data.
 ReportizFlow
ReportizFlow