Impact
IBM Cognos Analytics 12.1.3 is affected by a race condition in the Agentic AI assistant that can corrupt report summary data or trigger report-processing errors. The flaw exists because concurrent requests from authenticated users are not properly synchronized, resulting in data integrity failures and denial of service for analytical reporting, indicating a basic concurrency issue.
Affected Systems
All installations of IBM Cognos Analytics version 12.1.3 that have not yet been upgraded to build 12.1.3-2607110822 are vulnerable. The vulnerability is present in the GA package through build number 12.1.3-2606251736, as identified by the CPE strings and the IBM advisory. Customers running a 12.1.3 release must check their build version and apply the corrected package.
Risk and Exploitability
The CVSS score of 5.4 classifies the issue as moderate severity, and the EPSS score of less than 1% shows that the probability of exploitation is low. Because the flaw requires an authenticated user to create concurrent report tasks users already logged into Cognos. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread, active exploitation has been reported. Nonetheless, deploying the available fix will eliminate the risk of incorrect data or processing failures under concurrent usage.
OpenCVE Enrichment