Cognos Analytics
Vendor:
First CVE: Jul 2, 2016 · Active for 10 years
104
Total CVEs
More Total CVEs than 99% of tracked products
9.5
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 30% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Cognos Analytics over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 2, 2016
10 years ago
Most Recent CVE
May 27, 2026
62 days ago
CVE Severity & Scoring
Cognos Analytics104 CVEs
69%
23%
All CVEs353,173 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local9 (8.7%)
Network94 (90.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (1.0%)
Attack Complexity
Low100 (96.2%)
High4 (3.8%)
Unknown0 (0.0%)
User Interaction
None57 (54.8%)
Unknown0 (0.0%)
Required47 (45.2%)
Privileges Required
Low54 (51.9%)
High1 (1.0%)
None49 (47.1%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (104 CVEs).
104 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-38945CRITICAL IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 could allow a remote attacker to upload arbitrary files, caused by improper content validation. IBM X-Force ID: 211238. | Jun 24, 2022 | 9.8 | 32 | NO | NO |
CVE-2019-4178CRITICAL IBM Cognos Analytics 11 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request to write or view arbitrary files | Apr 15, 2019 | 9.1 | 30 | NO | NO |
CVE-2024-51466CRITICAL IBM Cognos Analytics 11.2.0 through 11.2.4 FP4 and
12.0.0 through 12.0.4
is vulnerable to an Expression Language (EL) Injection vulnerability. A remote attacker could exploit th | Dec 20, 2024 | 9.0 | 29 | NO | NO |
CVE-2025-3633HIGH IBM Cognos Analytics 11.2.0, 11.2.4, 12.0, and 12.1.0 and IBM Cognos Transformer 11.2.4, 12.0, and 12.1.0 are vulnerable to cross-site scripting (XSS). This vulnerability allows a | May 27, 2026 | 8.2 | 28 | NO | NO |
CVE-2025-36126HIGH IBM Cognos Analytics 11.2.0, 12.0, and 12.1.0 and IBM Cognos Transformer 12.0, 11.2.4, and 12.1.0 is vulnerable to stored cross-site scripting (XSS) in Cognos Adminstration. This v | May 26, 2026 | 7.6 | 28 | NO | NO |
CVE-2022-38708CRITICAL
IBM Cognos Analytics 11.1.7 11.2.0, and 11.2.1 could be vulnerable to a Server-Side Request Forgery Attack (SSRF) attack by constructing URLs from user-controlled data. This could | Dec 19, 2022 | 9.1 | 28 | NO | NO |
CVE-2021-38886HIGH IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted | Apr 22, 2022 | 8.8 | 28 | NO | NO |
CVE-2021-29756HIGH IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site request forgery (CSRF) in the My Inbox page which could allow an attacker to execute malicious and unauthorized a | Dec 3, 2021 | 8.8 | 28 | NO | NO |
CVE-2021-29745HIGH IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to priviledge escalation where a lower evel user could have access to the 'New Job' page to which they should not have access t | Oct 15, 2021 | 8.8 | 28 | NO | NO |
CVE-2021-29679HIGH IBM Cognos Analytics 11.1.7 and 11.2.0 could allow an authenticated user to execute code remotely due to incorrectly neutralizaing user-contrlled input that could be interpreted a | Oct 15, 2021 | 8.8 | 28 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (104 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (104 CVEs).
Media Mentions
Signals from CVEs in this product scope (104 CVEs).
Top CNAs Publishing CVEs For Cognos Analytics
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 12.0.4 | 8 | 7.4 | 0.4% | 0 | 0 |
| 12.0.3 | 2 | 6.8 | 0.2% | 0 | 0 |
| 12.0.2 | 2 | 6.8 | 0.2% | 0 | 0 |
| 12.0.1 | 7 | 5.9 | 0.5% | 0 | 0 |
| 12.0.0 | 7 | 5.9 | 0.5% | 0 | 0 |
| 11.2.4 | 24 | 6.7 | 0.4% | 0 | 0 |
| 11.2.3 | 2 | 6.8 | 0.2% | 0 | 0 |
| 11.2.2 | 2 | 6.8 | 0.2% | 0 | 0 |
| 11.2.1 | 13 | 6.4 | 0.9% | 0 | 0 |
| 11.2.0 | 23 | 6.5 | 0.9% | 0 | 0 |
| 11.2 | 2 | 6.8 | 0.4% | 0 | 0 |
| 11.1.7 | 42 | 6.2 | 0.7% | 0 | 0 |
| 11.1.1 | 1 | 5.4 | 1.0% | 0 | 0 |
| 11.1.0 | 21 | 6.6 | 1.7% | 0 | 0 |
| 11.1 | 1 | 6.1 | 0.5% | 0 | 0 |
| 11.0.7.0 | 3 | 5.8 | 0.4% | 0 | 0 |
| 11.0.6.0 | 3 | 5.8 | 0.4% | 0 | 0 |
| 11.0.6 | 5 | 5.7 | 0.8% | 0 | 0 |
| 11.0.5.0 | 3 | 5.8 | 0.4% | 0 | 0 |
| 11.0.5 | 5 | 5.7 | 0.8% | 0 | 0 |