CVE-2019-4176: IBM Cognos Controller

Medium severity, CVSS 5.3. EPSS: 1.9% chance of exploitation in the next 30 days.

IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 could allow a remote attacker to bypass security restrictions, caused by an error related to insecure HTTP Methods. An attacker could exploit this vulnerability to gain access to the system. IBM X-Force ID: 158881.

Affected products

  • IBM Cognos Controller: version 10.2.0 only; version 10.2.1 only; version 10.3.0 only; version 10.3.1 only; version 10.4.0 only

Published 2019-06-17. Last modified 2026-06-17.