Cognos Controller
Vendor:
First CVE: Jun 17, 2019 · Active for 7 years
52
Total CVEs
More Total CVEs than 98% of tracked products
10.4
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 28% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Cognos Controller over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 17, 2019
7 years ago
Most Recent CVE
Dec 8, 2025
229 days ago
CVE Severity & Scoring
Cognos Controller52 CVEs
12%
46%
31%
12%
All CVEs352,427 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local3 (5.8%)
Network49 (94.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low47 (90.4%)
High5 (9.6%)
Unknown0 (0.0%)
User Interaction
None46 (88.5%)
Unknown0 (0.0%)
Required6 (11.5%)
Privileges Required
Low19 (36.5%)
High3 (5.8%)
None30 (57.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (52 CVEs).
52 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-4879CRITICAL IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could allow a remote attacker to bypass security restrictions, caused by improper validation of authentication cookies. IBM X-Force | Jan 21, 2022 | 9.8 | 31 | NO | NO |
CVE-2020-4877CRITICAL IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could be vulnerable to unauthorized modifications by using public fields in public classes. IBM X-Force ID: 190843. | Jan 21, 2022 | 9.8 | 31 | NO | NO |
CVE-2024-25020CRITICAL IBM Cognos Controller 11.0.0 and 11.0.1
is vulnerable to malicious file upload by allowing unrestricted filetype attachments in the Journal entry page. Attackers can | Dec 3, 2024 | 9.8 | 29 | NO | NO |
CVE-2024-40691CRITICAL IBM Cognos Controller 11.0.0 and 11.0.1
could be vulnerable to malicious file upload by not validating the content of the file uploaded to the web interface. Attackers can make u | Dec 3, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-25019CRITICAL IBM Cognos Controller 11.0.0 and 11.0.1
could be vulnerable to malicious file upload by not validating the type of file uploaded to Journal entry attachments. Attackers can make | Dec 3, 2024 | 9.8 | 27 | NO | NO |
CVE-2023-38724CRITICAL IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to vi | May 3, 2024 | 9.8 | 27 | NO | NO |
CVE-2025-36326HIGH IBM Cognos Controller 11.0.0 through 11.0.1, and IBM Controller 11.1.0 through 11.1.1 could allow an attacker to obtain sensitive information due to the use of hardcoded cryptograp | Sep 26, 2025 | 7.5 | 24 | NO | NO |
CVE-2024-28777HIGH IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0
is vulnerable to unrestricted deserialization. This vulnerability allows users to execute arbitrary co | Feb 19, 2025 | 8.8 | 24 | NO | NO |
CVE-2024-52902HIGH IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 client application contains hard coded database passwords in source code which could be used for unauthori | Feb 19, 2025 | 8.8 | 24 | NO | NO |
CVE-2023-40695HIGH IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X- | May 3, 2024 | 8.8 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (52 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (52 CVEs).
Media Mentions
Signals from CVEs in this product scope (52 CVEs).
Top CNAs Publishing CVEs For Cognos Controller
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 11.0.1 | 11 | 6.9 | 0.3% | 0 | 0 |
| 11.0.0 | 21 | 6.8 | 0.3% | 0 | 0 |
| 10.4.2 | 15 | 7.3 | 0.8% | 0 | 0 |
| 10.4.1 | 19 | 6.9 | 0.8% | 0 | 0 |
| 10.4.0 | 14 | 6.3 | 1.1% | 0 | 0 |
| 10.3.1 | 9 | 4.9 | 1.0% | 0 | 0 |
| 10.3.0 | 9 | 4.9 | 1.0% | 0 | 0 |
| 10.2.1 | 5 | 4.8 | 1.0% | 0 | 0 |
| 10.2.0 | 5 | 4.8 | 1.0% | 0 | 0 |