CVE-2024-41752

IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
References
Link Resource
https://www.ibm.com/support/pages/node/7177223 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:cognos_analytics:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:*:*:*:*:*:*:*:*

History

10 Jan 2025, 19:33

Type Values Removed Values Added
Summary
  • (es) IBM Cognos Analytics 11.2.0 a 11.2.4 y 12.0.0 a 12.0.3 es vulnerable a la inyección de código HTML. Un atacante remoto podría inyectar código HTML malicioso que, al visualizarse, se ejecutaría en el navegador web de la víctima dentro del contexto de seguridad del sitio de alojamiento.
CWE CWE-79
References () https://www.ibm.com/support/pages/node/7177223 - () https://www.ibm.com/support/pages/node/7177223 - Vendor Advisory
CPE cpe:2.3:a:ibm:cognos_analytics:*:*:*:*:*:*:*:*
First Time Ibm cognos Analytics
Ibm

18 Dec 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-18 17:15

Updated : 2025-01-10 19:33


NVD link : CVE-2024-41752

Mitre link : CVE-2024-41752

CVE.ORG link : CVE-2024-41752


JSON object : View

Products Affected

ibm

  • cognos_analytics
CWE
CWE-80

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')