CVE-2018-1842: IBM Cognos Analytics
Low severity, CVSS 3.6. EPSS: 0.3% chance of exploitation in the next 30 days.
IBM Cognos Analytics 11 Configuration tool, under certain circumstances, will bypass OIDC namespace signature verification on its id_token. IBM X-Force ID: 150902.
Affected products
- IBM Cognos Analytics: from 11.0.0.0, up to and including 11.0.12.0
- Netapp Oncommand Insight: affected versions not specified
Published 2018-11-09. Last modified 2026-06-17.