Description
IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 could allow an attacker on a shared network to obtain sensitive information caused by insecure network communication.
Published: 2026-09-18
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Information Disclosure
Action: Patch Now
AI Analysis

Impact

The vulnerability arises from insecure network communication allowing an attacker on a shared network to obtain sensitive information. This weakness is classified as CWE-327, indicating improper cryptographic practices. Consequently, confidential data transmitted between the client and IBM Cognos Analytics could be intercepted or accessed by an unauthorized party.

Affected Systems

Affected deployments include IBM Cognos Analytics versions 12.1.0, 12.1.1, 12.1.2, 12.1.3, 12.1.3 FP1, 12.1.3 FP2 and 12.0.4, 12.0.4 FP2, 12.0.4 FP3. Versions outside these ranges are not impacted.

Risk and Exploitability

The CVSS base score of 5.9 reflects a moderate severity, but the EPSS score of < 1% and lack of listing in the KEV catalog suggest limited public exploitation at present. The attack vector is primarily network-based; the vulnerability can be triggered by a local actor on the same shared network segment. Although not a remote code execution flaw, an attacker can gain access to sensitive information, posing a moderate confidentiality risk.

Generated by OpenCVE AI on September 19, 2026 at 17:45 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. Affected Product(s)Version(s)Fix VersionIBM Cognos Analytics12.1.0, 12.1.1, 12.1.2, 12.1.3, 12.1.3 FP1 12.1.3 FP2 https://www.ibm.com/support/pages/node/7283969 IBM Cognos Analytics12.0.4 - 12.0.4 FP2 12.0.4 FP3 https://www.ibm.com/support/pages/node/7269268


OpenCVE Recommended Actions

  • Apply the latest IBM Cognos Analytics security patches, including 12.1.3 FP2 or later and 12.0.4 FP3 or later, to eliminate the insecure network communication flaw.
  • Restrict network access to Cognos Analytics servers by implementing firewall rules and limiting connectivity to trusted IP ranges.
  • Enable TLS encryption for all client-to-server communication to ensure sensitive data is protected during transit, following IBM’s secure configuration guidelines.
  • Consult the IBM security advisory at https://www.ibm.com/support/pages/node/7287209 for detailed guidance.

Generated by OpenCVE AI on September 19, 2026 at 17:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 could allow an attacker on a shared network to obtain sensitive information caused by insecure network communication.
Title IBM Cognos Analytics versions 12.0.4 and 12.1.3 is affected by security vulnerabilities
First Time appeared Ibm
Ibm cognos Analytics
Weaknesses CWE-327
CPEs cpe:2.3:a:ibm:cognos_analytics:12.0.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:12.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:12.1.3:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm cognos Analytics
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Ibm Cognos Analytics
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-21T14:05:27.186Z

Reserved: 2025-04-15T17:51:29.195Z

Link: CVE-2025-33147

cve-icon Vulnrichment

Updated: 2026-09-21T14:05:19.000Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T16:17:02.657

Modified: 2026-09-21T15:17:27.563

Link: CVE-2025-33147

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T18:00:14Z

Weaknesses
  • CWE-327

    Use of a Broken or Risky Cryptographic Algorithm