CVE-2018-1842: IBM Cognos Analytics

Low severity, CVSS 3.6. EPSS: 0.3% chance of exploitation in the next 30 days.

IBM Cognos Analytics 11 Configuration tool, under certain circumstances, will bypass OIDC namespace signature verification on its id_token. IBM X-Force ID: 150902.

Affected products

  • IBM Cognos Analytics: from 11.0.0.0, up to and including 11.0.12.0
  • Netapp Oncommand Insight: affected versions not specified

Published 2018-11-09. Last modified 2026-06-17.