CVE-2025-3633: IBM Cognos Analytics is affected by multiple security vulnerabilities
IBM Cognos Analytics 11.2.0, 11.2.4, 12.0, and 12.1.0 and IBM Cognos Transformer 11.2.4, 12.0, and 12.1.0 are vulnerable to cross-site scripting (XSS). This vulnerability allows a remote attacker to inject arbitrary JavaScript code into the web user interface, which may alter the intended functionality and could lead to the disclosure of credentials within a trusted session.
Other sources
IBM Cognos Analytics is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3633?
The severity of CVE-2025-3633 is medium with a score of 5.4.
How do I fix CVE-2025-3633?
To fix CVE-2025-3633, upgrade to the latest versions of IBM Cognos Analytics or IBM Cognos Transformer as recommended.
Which versions of IBM Cognos Analytics are affected by CVE-2025-3633?
IBM Cognos Analytics versions 11.2.0, 11.2.4, 12.0, and 12.1.0 are affected by CVE-2025-3633.
Is CVE-2025-3633 a cross-site scripting vulnerability?
Yes, CVE-2025-3633 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary JavaScript code.
Who is impacted by CVE-2025-3633?
Users of IBM Cognos Analytics and IBM Cognos Transformer versions stated in the vulnerability are impacted by CVE-2025-3633.