CVE-2024-25047
IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.2 is vulnerable to injection attacks in application logging by not sanitizing user provided data. This could lead to further attacks against the system. IBM X-Force ID: 282956.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.6
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
- EPSS probability
- 0.64%
- CWE
- CWE-117
- Published
- 2024-05-02
- Last modified
- 2026-03-13
Affected products
- IBM Cognos Analytics
Weakness type
Related vulnerabilities
- CVE-2026-25548 — InvoicePlane Vulnerable to Remote Code Execution via Local File Inclusion and Log Poisoning
- CVE-2024-47083 — Power Platform Terraform Provider has Improper Masking of Secrets in Logs
- CVE-2024-29022 — Session Hijacking via XSS attack in header and session grid in Xibo CMS
- CVE-2023-32712 — Unauthenticated Log Injection in Splunk Enterprise
- CVE-2023-4571 — Unauthenticated Log Injection in Splunk IT Service Intelligence (ITSI)
- CVE-2023-3997 — Unauthenticated Log Injection In Splunk SOAR
- CVE-2026-62948 — OpenWrt odhcpd/LuCI: unauthenticated DHCPv6 client can inject lease-file lines via FQDN hostname → stored XSS in the LuCI admin UI
- CVE-2026-81696 — openssl_encrypt before 1.4.9 Terminal Injection via info Command