CVE-2025-36126: IBM Cognos Analytics is affected by Cross-site scripting.
IBM Cognos Analytics 11.2.0, 12.0, and 12.1.0 and IBM Cognos Transformer 12.0, 11.2.4, and 12.1.0 is vulnerable to stored cross-site scripting (XSS) in Cognos Adminstration. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM Cognos Analytics is vulnerable to stored cross-site scripting (XSS) in Cognos Adminstration. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Cognos Analyticsto a version that resolves this vulnerability.Fixed in 12.0.4 Fix Pack 2 - Upgrade
Upgrade
IBM Cognos Analyticsto a version that resolves this vulnerability.Fixed in 12.1.2 - Compensating control
Because a privileged user can embed arbitrary JavaScript in the Cognos Administration Web UI and alter functionality (potentially leading to credentials disclosure within a trusted session), restrict access to the Cognos Administration Web UI to trusted/authorized users only.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36126?
The severity of CVE-2025-36126 is rated as medium with a score of 6.4.
How do I fix CVE-2025-36126?
To fix CVE-2025-36126, upgrade to the latest versions of IBM Cognos Analytics and IBM Cognos Transformer as recommended by IBM.
What types of applications are affected by CVE-2025-36126?
CVE-2025-36126 affects IBM Cognos Analytics versions 11.2.0, 12.0, 12.1.0 and IBM Cognos Transformer versions 12.0, 11.2.4, and 12.1.0.
What is the nature of the vulnerability in CVE-2025-36126?
CVE-2025-36126 involves stored cross-site scripting (XSS) vulnerabilities in the Cognos Administration interface.
Who is primarily at risk from CVE-2025-36126?
Priilvileged users of IBM Cognos Analytics and Cognos Transformer are primarily at risk from CVE-2025-36126 due to the ability to embed arbitrary JavaScript.