CVE-2024-49352: IBM Cognos Analytics
High severity, CVSS 7.1. EPSS: 0.5% chance of exploitation in the next 30 days.
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
Affected products
- IBM Cognos Analytics: from 11.2.0, before 11.2.4 (fixed in 11.2.4); from 12.0.0, before 12.0.4 (fixed in 12.0.4); version 11.2.4 only; version 12.0.4 only
Published 2025-02-05. Last modified 2026-06-17.