CVE-2023-32344: IBM Cognos Analytics

Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.

IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 is vulnerable to form action hijacking where it is possible to modify the form action to reference an arbitrary path. IBM X-Force ID: 255898.

Affected products

  • IBM Cognos Analytics: from 11.1.1, before 11.1.7 (fixed in 11.1.7); from 11.2.0, before 11.2.4 (fixed in 11.2.4); version 11.1.7 only; version 11.2.4 only; version 12.0.0 only; version 12.0.1 only
  • Netapp Oncommand Insight: affected versions not specified

Published 2024-02-26. Last modified 2026-06-17.