IBMCVE-2026-7884
IBM Cognos Analytics: cross-site scripting
Medium5.4CVE-2026-7884 · Published Sep 14, 2026 · updated Sep 16, 2026
IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 allows a non-privileged user to edit their given name and surname to include malicious JavaScript code. When an administrator later accesses the user account management panel and views that user's permissions, the malicious JavaScript code is executed. This could result in the cookies from the administrator being compromised.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Cognos Analytics Product | >= 12.1.0, <= 12.1.3 FP1 | No fix yet |
| >= 12.0.4, <= 12.0.4 FP2 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-79
More IBM advisories
All IBM| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 14 | IBM MQ: information disclosure | Medium6.8 | No fix yet |
| Sep 14 | IBM Business Automation Workflow containers and traditional: XML external entity | High7.1 | No fix yet |
| Sep 14 | IBM Cloud Pak for Business Automation: missing authorization | Medium5.4 | No fix yet |
| Sep 14 | IBM Cloud Pak for Business Automation: denial of service | Medium6.5 | No fix yet |
| Sep 14 | IBM Langflow OSS: server-side request forgery | Critical9.6 | No fix yet |
| Sep 14 | IBM Sterling Secure Proxy: improper authorization | Medium4.3 | No fix yet |