cve/2024/CVE-2024-25041.md

18 lines
983 B
Markdown
Raw Permalink Normal View History

2025-09-29 21:09:30 +02:00
### [CVE-2024-25041](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-25041)
![](https://img.shields.io/static/v1?label=Product&message=Cognos%20Analytics&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=11.2.0%2C%2011.2.1%2C%2011.2.2%2C%2011.2.3%2C%2011.2.4%2C%2012.0.0%2C%2012.0.1%2C%2012.0.2%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-79%20Improper%20Neutralization%20of%20Input%20During%20Web%20Page%20Generation%20(XSS%20or%20'Cross-site%20Scripting')&color=brightgreen)
### Description
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, and 12.0.2 is potentially vulnerable to cross site scripting (XSS). A remote attacker could execute malicious commands due to improper validation of column headings in Cognos Assistant. IBM X-Force ID: 282780.
### POC
#### Reference
- https://www.ibm.com/support/pages/node/7156941
#### Github
No PoCs found on GitHub currently.