← Back

CVE-2025-36126

nvd nist
Published: May 26, 2026Modified: Jul 24, 2026

JSON object

Loading...
7.6
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
Exploitability: 2.3 / Impact: 4.7
Source: NVD

Description

IBM Cognos Analytics 11.2.0, 12.0, and 12.1.0 and IBM Cognos Transformer 12.0, 11.2.4, and 12.1.0 is vulnerable to stored cross-site scripting (XSS) in Cognos Adminstration. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

Affected (32)

2 products
Cognos Analytics
Cognos Transformer
Configuration A
32 vulnerable
Vulnerable SoftwareAffected Versions
Ibm
From 12.1.0 to 12.1.2
Version 11.2.0
Version 11.2.1
Version 11.2.2
Version 11.2.3
Version 11.2.4
Version 11.2.4 fixpack1
Version 11.2.4 fixpack2
Version 11.2.4 fixpack3
Version 11.2.4 fixpack4
Version 11.2.4 fixpack5
Version 11.2.4 fixpack6
Version 11.2.4 interim_fix_1
Version 11.2.4 interim_fix_2
Version 11.2.4 interim_fix_3
Version 11.2.4 interim_fix_4
Version 11.2.4 interim_fix_5
Version 11.2
Version 12.0.0
Version 12.0.1
Version 12.0.2
Version 12.0.3
Version 12.0.3 interim_fix_1
Version 12.0.3 interim_fix_2
Version 12.0.4
Version 12.0.4 fixpack1
Version 12.0.4 interim_fix_1
Version 12.0.4 interim_fix_2
Version 12.0.4 interim_fix_3
Ibm
Version 11.2.4
Version 12.0
Version 12.1.0

References (1)

Source: psirt@us.ibm.com
Vendor Advisory

Timeline

No history available yet.