← Back

CVE-2025-3633

nvd nist
Published: May 27, 2026Modified: Jun 17, 2026

JSON object

Loading...
8.2
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Exploitability: 2.8 / Impact: 4.7
Source: NVD

Description

IBM Cognos Analytics 11.2.0, 11.2.4, 12.0, and 12.1.0 and IBM Cognos Transformer 11.2.4, 12.0, and 12.1.0 are vulnerable to cross-site scripting (XSS). This vulnerability allows a remote attacker to inject arbitrary JavaScript code into the web user interface, which may alter the intended functionality and could lead to the disclosure of credentials within a trusted session.

Affected (21)

2 products
Cognos Analytics
Cognos Transformer
Configuration A
21 vulnerable
Vulnerable SoftwareAffected Versions
Ibm
From 11.2.0 to 11.2.4
From 12.0.0 to 12.0.4
From 12.1.0 to 12.1.2
Version 11.2.4
Version 11.2.4 fixpack1
Version 11.2.4 fixpack2
Version 11.2.4 fixpack3
Version 11.2.4 fixpack4
Version 11.2.4 fixpack5
Version 11.2.4 fixpack6
Version 11.2.4 interim_fix_1
Version 11.2.4 interim_fix_2
Version 11.2.4 interim_fix_3
Version 11.2.4 interim_fix_4
Version 11.2.4 interim_fix_5
Version 12.0.4 interim_fix_1
Version 12.0.4 interim_fix_2
Version 12.0.4 interim_fix_3
Ibm
Version 11.2.4
Version 12.0
Version 12.1.0

References (1)

Source: psirt@us.ibm.com
Vendor Advisory

Timeline

No history available yet.