Cognos Controller

Vendor:

First CVE: Jun 17, 2019 · Active for 7 years

52
Total CVEs
More Total CVEs than 98% of tracked products
10.4
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 28% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Cognos Controller over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 17, 2019
7 years ago
Most Recent CVE
Dec 8, 2025
229 days ago

CVE Severity & Scoring

Cognos Controller52 CVEs
All CVEs352,427 CVEs
LowMediumHighCritical
Attack Vector
Local3 (5.8%)
Network49 (94.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low47 (90.4%)
High5 (9.6%)
Unknown0 (0.0%)
User Interaction
None46 (88.5%)
Unknown0 (0.0%)
Required6 (11.5%)
Privileges Required
Low19 (36.5%)
High3 (5.8%)
None30 (57.7%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (52 CVEs).

52 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could allow a remote attacker to bypass security restrictions, caused by improper validation of authentication cookies. IBM X-Force
Jan 21, 20229.831NONO
IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could be vulnerable to unauthorized modifications by using public fields in public classes. IBM X-Force ID: 190843.
Jan 21, 20229.831NONO
IBM Cognos Controller 11.0.0 and 11.0.1 is vulnerable to malicious file upload by allowing unrestricted filetype attachments in the Journal entry page. Attackers can
Dec 3, 20249.829NONO
IBM Cognos Controller 11.0.0 and 11.0.1 could be vulnerable to malicious file upload by not validating the content of the file uploaded to the web interface. Attackers can make u
Dec 3, 20249.827NONO
IBM Cognos Controller 11.0.0 and 11.0.1 could be vulnerable to malicious file upload by not validating the type of file uploaded to Journal entry attachments. Attackers can make
Dec 3, 20249.827NONO
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to vi
May 3, 20249.827NONO
IBM Cognos Controller 11.0.0 through 11.0.1, and IBM Controller 11.1.0 through 11.1.1 could allow an attacker to obtain sensitive information due to the use of hardcoded cryptograp
Sep 26, 20257.524NONO
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to unrestricted deserialization. This vulnerability allows users to execute arbitrary co
Feb 19, 20258.824NONO
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 client application contains hard coded database passwords in source code which could be used for unauthori
Feb 19, 20258.824NONO
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-
May 3, 20248.824NONO

Exploit Exposure

Signals from CVEs in this product scope (52 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (52 CVEs).

Media Mentions

Signals from CVEs in this product scope (52 CVEs).

Top CNAs Publishing CVEs For Cognos Controller

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
11.0.1116.90.3%00
11.0.0216.80.3%00
10.4.2157.30.8%00
10.4.1196.90.8%00
10.4.0146.31.1%00
10.3.194.91.0%00
10.3.094.91.0%00
10.2.154.81.0%00
10.2.054.81.0%00