Cross Site Scripting Vulnerability in IBM Cognos Analytics
CVE-2024-25042
6.1MEDIUM
What is CVE-2024-25042?
IBM Cognos Analytics versions 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 are susceptible to a Cross Site Scripting (XSS) vulnerability. This issue arises from improper validation of column headings within Cognos Explorations, which could allow a remote attacker to execute harmful commands on the affected applications, potentially compromising the security of the entire system.