Description
IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 allows a non-privileged user to edit their given name and surname to include malicious JavaScript code. When an administrator later accesses the user account management panel and views that user's permissions, the malicious JavaScript code is executed. This could result in the cookies from the administrator being compromised.
Published: 2026-09-14
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting that can lead to theft of administrator session cookies
Action: Immediate Patch
AI Analysis

Impact

A non‑privileged user can edit their first and last name fields to contain malicious JavaScript. When an administrator later accesses that user’s account in the management console, the injected script is executed in the administrator’s browser, allowing the attacker to steal the administrator’s session cookies. The flaw falls under CWE‑79, reflecting a reflected or stored XSS vulnerability.

Affected Systems

IBM Cognos Analytics versions 12.1.0 through 12.1.3 up to FP1 and 12.0.4 through 12.0.4 up to FP2 are affected. The recommended remedial versions are IBM Cognos Analytics 12.1.3 FP2 and IBM Cognos Analytics 12.0.4 FP3.

Risk and Exploitability

The CVSS score of 5.4 indicates a moderate risk. The EPSS score is below 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in CISA KEV. The likely attack vector involves a regular user updating personal information; exploitation requires no special privileges beyond a normal user account. Once the script executes in an administrator’s session, the attacker can retrieve sensitive cookies, potentially compromising the administrator’s access rights. The overall risk is mitigated only by applying the vendor patches or equivalent controls.

Generated by OpenCVE AI on September 17, 2026 at 19:26 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. Affected Product(s)Version(s)Fix VersionIBM Cognos Analytics12.1.0, 12.1.1, 12.1.2, 12.1.3, 12.1.3 FP1 12.1.3 FP2 https://www.ibm.com/support/pages/node/7283969 IBM Cognos Analytics12.0.4 - 12.0.4 FP2 12.0.4 FP3 https://www.ibm.com/support/pages/node/7269268


OpenCVE Recommended Actions

  • Apply the latest IBM Cognos Analytics patch (12.1.3 FP2 or 12.0.4 FP3) immediately.
  • Restrict the ability for non‑administrator users to modify their name fields, or remove the JavaScript‑accepting attribute from those inputs.
  • Enforce a Content‑Security‑Policy in the Cognos web interface to block inline script execution, thereby limiting the impact of any remaining XSS payloads.

Generated by OpenCVE AI on September 17, 2026 at 19:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 allows a non-privileged user to edit their given name and surname to include malicious JavaScript code. When an administrator later accesses the user account management panel and views that user's permissions, the malicious JavaScript code is executed. This could result in the cookies from the administrator being compromised.
Title IBM Cognos Analytics versions 12.0.4 and 12.1.3 is affected by security vulnerabilities
First Time appeared Ibm
Ibm cognos Analytics
Weaknesses CWE-79
CPEs cpe:2.3:a:ibm:cognos_analytics:12.0.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:12.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:12.1.3:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm cognos Analytics
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Ibm Cognos Analytics
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-15T17:31:47.874Z

Reserved: 2026-05-05T19:25:30.587Z

Link: CVE-2026-7884

cve-icon Vulnrichment

Updated: 2026-09-15T17:26:59.039Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T21:17:25.983

Modified: 2026-09-16T19:24:44.153

Link: CVE-2026-7884

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T22:00:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')