Insecure Network Communication in IBM Cognos Analytics Affects User Data
CVE-2025-33147

5.9MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
18 September 2026

What is CVE-2025-33147?

IBM Cognos Analytics versions 12.1.0 to 12.1.3 FP1 and 12.0.4 to 12.0.4 FP2 contain a vulnerability that can be exploited by an attacker on a shared network. This weakness allows unauthorized access to sensitive information due to the lack of secure communication protocols, posing a significant risk to data integrity and privacy for organizations relying on this analytics platform. Users are encouraged to implement recommended mitigations and updates to safeguard against potential exploitation.

Affected Version(s)

Cognos Analytics 12.1.0 <= 12.1.3 FP1

Cognos Analytics 12.0.4 <= 12.0.4 FP2

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.