CVE-2020-4301: IBM Cognos Analytics
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 176609.
Affected products
- IBM Cognos Analytics: from 11.1.0, before 11.1.7 (fixed in 11.1.7); from 11.2.0, before 11.2.3 (fixed in 11.2.3); version 11.1.7 only
- Netapp Oncommand Insight: affected versions not specified
Published 2022-09-01. Last modified 2026-06-17.