Impact
A non‑privileged user can edit their first and last name fields to contain malicious JavaScript. When an administrator later accesses that user’s account in the management console, the injected script is executed in the administrator’s browser, allowing the attacker to steal the administrator’s session cookies. The flaw falls under CWE‑79, reflecting a reflected or stored XSS vulnerability.
Affected Systems
IBM Cognos Analytics versions 12.1.0 through 12.1.3 up to FP1 and 12.0.4 through 12.0.4 up to FP2 are affected. The recommended remedial versions are IBM Cognos Analytics 12.1.3 FP2 and IBM Cognos Analytics 12.0.4 FP3.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate risk. The EPSS score is below 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in CISA KEV. The likely attack vector involves a regular user updating personal information; exploitation requires no special privileges beyond a normal user account. Once the script executes in an administrator’s session, the attacker can retrieve sensitive cookies, potentially compromising the administrator’s access rights. The overall risk is mitigated only by applying the vendor patches or equivalent controls.
OpenCVE Enrichment