Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
IBM strongly recommends addressing the vulnerability now. Affected Product(s)Version(s)Fix VersionIBM Cognos Analytics12.1.0, 12.1.1, 12.1.2, 12.1.3, 12.1.3 FP1 12.1.3 FP2 https://www.ibm.com/support/pages/node/7283969 IBM Cognos Analytics12.0.4 - 12.0.4 FP2 12.0.4 FP3 https://www.ibm.com/support/pages/node/7269268
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7287209 |
|
Mon, 14 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 allows a non-privileged user to edit their given name and surname to include malicious JavaScript code. When an administrator later accesses the user account management panel and views that user's permissions, the malicious JavaScript code is executed. This could result in the cookies from the administrator being compromised. | |
| Title | IBM Cognos Analytics versions 12.0.4 and 12.1.3 is affected by security vulnerabilities | |
| First Time appeared |
Ibm
Ibm cognos Analytics |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:ibm:cognos_analytics:12.0.4:*:*:*:*:*:*:* cpe:2.3:a:ibm:cognos_analytics:12.1.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:cognos_analytics:12.1.3:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm cognos Analytics |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-09-14T20:55:46.371Z
Reserved: 2026-05-05T19:25:30.587Z
Link: CVE-2026-7884
No data.
Status : Received
Published: 2026-09-14T21:17:25.983
Modified: 2026-09-14T21:17:25.983
Link: CVE-2026-7884
No data.
OpenCVE Enrichment
No data.
