Impact
A failure to enable HTTP Strict Transport Security (HSTS) in IBM Cognos Analytics opens the application to man‑in‑the‑middle attacks. The absence of HSTS allows an attacker to downgrade or intercept HTTP traffic, capturing sensitive data transmitted between the client and the server. This weakness is classified as CWE‑327, indicating improper or weakened cryptographic handling.
Affected Systems
IBM Cognos Analytics versions 12.0.4 through 12.0.4 FP2 and 12.1.0 through 12.1.3 FP1 are affected. The issue is resolved in later releases: 12.0.4 FP3 and 12.1.3 FP2.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity. No EPSS data is available and the flaw is not listed in CISA KEV. The likely attack vector is a remote attacker capable of intercepting or downgrading HTTPS traffic, such as via a compromised network point or MITM device, which would enable the disclosure of confidential information.
OpenCVE Enrichment