Description
IBM Cognos Analytics 12.0.4 through 12.0.4 FP2, and 12.1.0 through 12.1.3 FP1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
Published: 2026-09-18
Score: 5.9 Medium
EPSS: n/a
KEV: No
Impact: Remote Information Disclosure via HSTS misconfiguration
Action: Apply patch
AI Analysis

Impact

A failure to enable HTTP Strict Transport Security (HSTS) in IBM Cognos Analytics opens the application to man‑in‑the‑middle attacks. The absence of HSTS allows an attacker to downgrade or intercept HTTP traffic, capturing sensitive data transmitted between the client and the server. This weakness is classified as CWE‑327, indicating improper or weakened cryptographic handling.

Affected Systems

IBM Cognos Analytics versions 12.0.4 through 12.0.4 FP2 and 12.1.0 through 12.1.3 FP1 are affected. The issue is resolved in later releases: 12.0.4 FP3 and 12.1.3 FP2.

Risk and Exploitability

The CVSS score of 5.9 indicates moderate severity. No EPSS data is available and the flaw is not listed in CISA KEV. The likely attack vector is a remote attacker capable of intercepting or downgrading HTTPS traffic, such as via a compromised network point or MITM device, which would enable the disclosure of confidential information.

Generated by OpenCVE AI on September 18, 2026 at 23:09 UTC.

Remediation

Vendor Solution

Affected Product(s)Version(s)Fix VersionIBM Cognos Analytics12.0.4 12.0.4 FP3 https://www.ibm.com/support/pages/node/7283969 IBM Cognos Analytics12.1.3 12.1.3 FP2 https://www.ibm.com/support/pages/node/7269268


OpenCVE Recommended Actions

  • Apply IBM’s latest fix pack—12.0.4 FP3 for the 12.0.4 line or 12.1.3 FP2 for the 12.1.3 line—to enable HSTS.
  • If the system cannot be updated immediately, configure a reverse proxy or TLS termination that injects a strict‑transport‑security header and forces secure connections to Cognos.
  • Implement monitoring of network traffic to detect HTTP downgrade or man‑in‑the‑middle attempts targeting Cognos and investigate any anomalies.

Generated by OpenCVE AI on September 18, 2026 at 23:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description IBM Cognos Analytics 12.0.4 through 12.0.4 FP2, and 12.1.0 through 12.1.3 FP1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
Title IBM Cognos Analytics 12.0.4 and 12.1.3 versions are affected by security vulnerabilities
First Time appeared Ibm
Ibm cognos Analytics
Weaknesses CWE-327
CPEs cpe:2.3:a:ibm:cognos_analytics:12.0.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:12.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:12.1.3:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm cognos Analytics
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Ibm Cognos Analytics
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-18T14:29:49.590Z

Reserved: 2024-12-20T13:55:07.213Z

Link: CVE-2024-56344

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T15:17:03.947

Modified: 2026-09-18T18:17:47.257

Link: CVE-2024-56344

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T23:15:17Z

Weaknesses
  • CWE-327

    Use of a Broken or Risky Cryptographic Algorithm