CVE-2023-30996: IBM Cognos Analytics

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 could be vulnerable to information leakage due to unverified sources in messages sent between Windows objects of different origins. IBM X-Force ID: 254290.

Affected products

  • IBM Cognos Analytics: from 11.1.1, before 11.1.7 (fixed in 11.1.7); from 11.2.0, before 11.2.4 (fixed in 11.2.4); version 11.1.7 only; version 11.2.4 only; version 12.0.0 only; version 12.0.1 only
  • Netapp Oncommand Insight: affected versions not specified

Published 2024-02-26. Last modified 2026-06-17.