CVE-2024-52900: IBM Cognos Analytics cross-site scripting
IBM Cognos Analytics 11.2.0 through 12.2.4 Fix Pack 5 and 12.0.0 through 12.0.4 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM Cognos Analytics is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Remediation
Information
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-52900?
The severity of CVE-2024-52900 is classified as medium, as it allows for stored cross-site scripting vulnerabilities in IBM Cognos Analytics.
How do I fix CVE-2024-52900?
To fix CVE-2024-52900, you should update IBM Cognos Analytics to a patched version beyond 12.2.4 or 12.0.4 Fix Pack 5.
Who is affected by CVE-2024-52900?
CVE-2024-52900 affects authenticated users of IBM Cognos Analytics versions 11.2.0 through 12.2.4 Fix Pack 5 and 12.0.0 through 12.0.4.
What kind of attack can CVE-2024-52900 enable?
CVE-2024-52900 can enable attackers to execute arbitrary JavaScript in the Web UI, leading to potential data manipulation and unauthorized access.
Is CVE-2024-52900 being actively exploited?
As of now, there are no reported active exploitation attempts for CVE-2024-52900 in the wild, but it remains critically important to apply patches.