CVE-2024-25047: IBM Cognos Analytics

High severity, CVSS 8.6. EPSS: 0.6% chance of exploitation in the next 30 days.

IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.2 is vulnerable to injection attacks in application logging by not sanitizing user provided data. This could lead to further attacks against the system. IBM X-Force ID: 282956.

Affected products

  • IBM Cognos Analytics: from 11.2.0, before 11.2.4 (fixed in 11.2.4); from 12.0.0, before 12.0.3 (fixed in 12.0.3); version 11.2.4 only
  • Netapp Oncommand Insight: affected versions not specified

Published 2024-05-02. Last modified 2026-06-17.