CVE-2024-45082: IBM Cognos Analytics

Medium severity, CVSS 5.2. EPSS: 0.2% chance of exploitation in the next 30 days.

IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted.

Affected products

  • IBM Cognos Analytics: from 11.2.0, up to and including 11.2.4; from 12.0.0, up to and including 12.0.3

Published 2024-12-18. Last modified 2026-06-17.