Refine your search

8 vulnerabilities found for Cognos Command Center by IBM

CERTFR-2026-AVI-0933
Vulnerability from certfr_avis

De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.

Solutions

Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

Impacted products
Vendor Product Description
IBM QRadar Assistant QRadar AI Assistant versions antérieures à 2.1.0
IBM Sterling Sterling B2B Integrator et Sterling File Gateway versions 6.2.2.x antérieures à 6.2.2.1
IBM Sterling Sterling B2B Integrator et Sterling File Gateway versions 6.2.1.x antérieures à 6.2.1.2
IBM QRadar SIEM QRadar SIEM versions 7.5.x antérieures à 7.5.0 UP15 IF05
IBM Sterling Sterling Connect:Direct Web Services versions 6.4.x antérieures à 6.4.0.9
IBM Tivoli Tivoli System Automation Application Manager 4.1 avec WebSphere Application Server versions 8.5 ou 9.0 sans les derniers correctifs de sécurité
IBM Cognos Command Center Cognos Command Center versions 12.2.4.1 à 12.2.5 FP1 IF3 antérieures à 12.2.5 FP1 IF4
IBM AIX AIX versions 7.2 et 7.3 sans le dernier correctif de sécurité
IBM Sterling Sterling Connect:Direct Web Services versions 6.3.x antérieures à 6.3.0.20
IBM Sterling Sterling B2B Integrator et Sterling File Gateway versions 6.2.0.x antérieures à 6.2.0.6_1
IBM WebSphere WebSphere Application Server - Liberty versions 17.0.0.3 à 26.0.0.7 sans les correctifs de sécurité temporaires PH71839 et PH72167 ou antérieures à 26.0.0.8 (disponibilité prévue pour le troisième trimestre 2026)
IBM Tivoli Tivoli Composite Application Manager for Applications WebSphere MQ Monitoring Agent version 7.3.0 Fix Pack 4 sans le dernier correctif pour Tivoli Monitoring
IBM VIOS VIOS version 4.1 sans le dernier correctif de sécurité
IBM Sterling Sterling B2B Integrator et Sterling File Gateway versions 6.1.2.x antérieures à 6.1.2.8
IBM Tivoli Tivoli Application Dependency Discovery Manager versions 7.3.0.0 à 7.3.0.12 avec WebSphere Application Server Liberty versions antérieures à 26.0.0.7
References
Bulletin de sécurité IBM 7280728 2026-07-22 vendor-advisory
Bulletin de sécurité IBM 7280784 2026-07-22 vendor-advisory
Bulletin de sécurité IBM 7280667 2026-07-21 vendor-advisory
Bulletin de sécurité IBM 7280663 2026-07-21 vendor-advisory
Bulletin de sécurité IBM 7280907 2026-07-23 vendor-advisory
Bulletin de sécurité IBM 7280731 2026-07-22 vendor-advisory
Bulletin de sécurité IBM 7280720 2026-07-22 vendor-advisory
Bulletin de sécurité IBM 7281073 2026-07-24 vendor-advisory
Bulletin de sécurité IBM 7280519 2026-07-20 vendor-advisory
Bulletin de sécurité IBM 7280540 2026-07-20 vendor-advisory
Bulletin de sécurité IBM 7280730 2026-07-22 vendor-advisory
Bulletin de sécurité IBM 7280726 2026-07-22 vendor-advisory
Bulletin de sécurité IBM 7280783 2026-07-22 vendor-advisory
Bulletin de sécurité IBM 7280650 2026-07-21 vendor-advisory
Bulletin de sécurité IBM 7280654 2026-07-21 vendor-advisory
Bulletin de sécurité IBM 7280644 2026-07-21 vendor-advisory
Bulletin de sécurité IBM 7280729 2026-07-22 vendor-advisory
Bulletin de sécurité IBM 7280785 2026-07-22 vendor-advisory
Bulletin de sécurité IBM 7280695 2026-07-21 vendor-advisory
Bulletin de sécurité IBM 7280719 2026-07-22 vendor-advisory
Bulletin de sécurité IBM 7280727 2026-07-22 vendor-advisory
Bulletin de sécurité IBM 7280646 2026-07-21 vendor-advisory
Bulletin de sécurité IBM 7280670 2026-07-22 vendor-advisory
Bulletin de sécurité IBM 7280916 2026-07-23 vendor-advisory
Bulletin de sécurité IBM 7280950 2026-07-23 vendor-advisory
Bulletin de sécurité IBM 7280126 2026-07-21 vendor-advisory
Bulletin de sécurité IBM 7280656 2026-07-21 vendor-advisory
Bulletin de sécurité IBM 7280621 2026-07-22 vendor-advisory
Bulletin de sécurité IBM 7280887 2026-07-23 vendor-advisory

Show details on source website


{
  "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
  "affected_systems": [
    {
      "description": "QRadar AI Assistant versions ant\u00e9rieures \u00e0 2.1.0",
      "product": {
        "name": "QRadar Assistant",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Sterling B2B Integrator et Sterling File Gateway versions 6.2.2.x ant\u00e9rieures \u00e0 6.2.2.1",
      "product": {
        "name": "Sterling",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Sterling B2B Integrator et Sterling File Gateway versions 6.2.1.x ant\u00e9rieures \u00e0 6.2.1.2",
      "product": {
        "name": "Sterling",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "QRadar SIEM versions 7.5.x ant\u00e9rieures \u00e0 7.5.0 UP15 IF05",
      "product": {
        "name": "QRadar SIEM",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Sterling Connect:Direct Web Services versions 6.4.x ant\u00e9rieures \u00e0 6.4.0.9",
      "product": {
        "name": "Sterling",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Tivoli System Automation Application Manager 4.1 avec WebSphere Application Server versions 8.5 ou 9.0 sans les derniers correctifs de s\u00e9curit\u00e9",
      "product": {
        "name": "Tivoli",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Cognos Command Center versions 12.2.4.1 \u00e0 12.2.5 FP1 IF3 ant\u00e9rieures \u00e0 12.2.5 FP1 IF4",
      "product": {
        "name": "Cognos Command Center",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "AIX versions 7.2 et 7.3 sans le dernier correctif de s\u00e9curit\u00e9",
      "product": {
        "name": "AIX",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Sterling Connect:Direct Web Services versions 6.3.x ant\u00e9rieures \u00e0 6.3.0.20",
      "product": {
        "name": "Sterling",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Sterling B2B Integrator et Sterling File Gateway versions 6.2.0.x ant\u00e9rieures \u00e0 6.2.0.6_1",
      "product": {
        "name": "Sterling",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "WebSphere Application Server - Liberty versions 17.0.0.3 \u00e0 26.0.0.7 sans les correctifs de s\u00e9curit\u00e9 temporaires PH71839 et PH72167 ou ant\u00e9rieures \u00e0 26.0.0.8 (disponibilit\u00e9 pr\u00e9vue pour le troisi\u00e8me trimestre 2026)",
      "product": {
        "name": "WebSphere",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Tivoli Composite Application Manager for Applications WebSphere MQ Monitoring Agent version 7.3.0 Fix Pack 4 sans le dernier correctif pour Tivoli Monitoring",
      "product": {
        "name": "Tivoli",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "VIOS version 4.1 sans le dernier correctif de s\u00e9curit\u00e9",
      "product": {
        "name": "VIOS",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Sterling B2B Integrator et Sterling File Gateway versions 6.1.2.x ant\u00e9rieures \u00e0 6.1.2.8",
      "product": {
        "name": "Sterling",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Tivoli Application Dependency Discovery Manager versions 7.3.0.0 \u00e0 7.3.0.12 avec WebSphere Application Server Liberty versions ant\u00e9rieures \u00e0 26.0.0.7",
      "product": {
        "name": "Tivoli",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    }
  ],
  "affected_systems_content": "",
  "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
  "cves": [
    {
      "name": "CVE-2026-53540",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53540"
    },
    {
      "name": "CVE-2026-54283",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54283"
    },
    {
      "name": "CVE-2026-50557",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50557"
    },
    {
      "name": "CVE-2026-33871",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33871"
    },
    {
      "name": "CVE-2026-48990",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48990"
    },
    {
      "name": "CVE-2026-11383",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11383"
    },
    {
      "name": "CVE-2026-34180",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34180"
    },
    {
      "name": "CVE-2026-45416",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45416"
    },
    {
      "name": "CVE-2026-42766",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42766"
    },
    {
      "name": "CVE-2026-9076",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9076"
    },
    {
      "name": "CVE-2026-42211",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42211"
    },
    {
      "name": "CVE-2026-54530",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54530"
    },
    {
      "name": "CVE-2026-54514",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54514"
    },
    {
      "name": "CVE-2021-23336",
      "url": "https://www.cve.org/CVERecord?id=CVE-2021-23336"
    },
    {
      "name": "CVE-2026-48710",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48710"
    },
    {
      "name": "CVE-2026-42770",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42770"
    },
    {
      "name": "CVE-2026-24308",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24308"
    },
    {
      "name": "CVE-2026-45673",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45673"
    },
    {
      "name": "CVE-2026-9072",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9072"
    },
    {
      "name": "CVE-2026-54275",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54275"
    },
    {
      "name": "CVE-2026-32635",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32635"
    },
    {
      "name": "CVE-2026-27171",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27171"
    },
    {
      "name": "CVE-2026-45445",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45445"
    },
    {
      "name": "CVE-2026-29145",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-29145"
    },
    {
      "name": "CVE-2026-8858",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8858"
    },
    {
      "name": "CVE-2026-54651",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54651"
    },
    {
      "name": "CVE-2026-54278",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54278"
    },
    {
      "name": "CVE-2026-54516",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54516"
    },
    {
      "name": "CVE-2026-53538",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53538"
    },
    {
      "name": "CVE-2026-2006",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2006"
    },
    {
      "name": "CVE-2026-54515",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54515"
    },
    {
      "name": "CVE-2026-33245",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33245"
    },
    {
      "name": "CVE-2026-33870",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33870"
    },
    {
      "name": "CVE-2025-5115",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-5115"
    },
    {
      "name": "CVE-2021-47154",
      "url": "https://www.cve.org/CVERecord?id=CVE-2021-47154"
    },
    {
      "name": "CVE-2026-11541",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11541"
    },
    {
      "name": "CVE-2026-11707",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11707"
    },
    {
      "name": "CVE-2026-2005",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2005"
    },
    {
      "name": "CVE-2026-7383",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7383"
    },
    {
      "name": "CVE-2026-48522",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48522"
    },
    {
      "name": "CVE-2026-45674",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45674"
    },
    {
      "name": "CVE-2026-34500",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34500"
    },
    {
      "name": "CVE-2026-11594",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11594"
    },
    {
      "name": "CVE-2026-54267",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54267"
    },
    {
      "name": "CVE-2026-29146",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-29146"
    },
    {
      "name": "CVE-2026-48735",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48735"
    },
    {
      "name": "CVE-2026-15057",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15057"
    },
    {
      "name": "CVE-2026-45409",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45409"
    },
    {
      "name": "CVE-2026-47265",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47265"
    },
    {
      "name": "CVE-2026-54282",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54282"
    },
    {
      "name": "CVE-2026-44249",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44249"
    },
    {
      "name": "CVE-2026-41844",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41844"
    },
    {
      "name": "CVE-2026-48988",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48988"
    },
    {
      "name": "CVE-2026-54268",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54268"
    },
    {
      "name": "CVE-2026-5598",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5598"
    },
    {
      "name": "CVE-2026-54277",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54277"
    },
    {
      "name": "CVE-2026-41842",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41842"
    },
    {
      "name": "CVE-2026-11536",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11536"
    },
    {
      "name": "CVE-2026-8646",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8646"
    },
    {
      "name": "CVE-2026-54280",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54280"
    },
    {
      "name": "CVE-2026-27970",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27970"
    },
    {
      "name": "CVE-2026-9320",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9320"
    },
    {
      "name": "CVE-2026-54265",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54265"
    },
    {
      "name": "CVE-2025-68161",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-68161"
    },
    {
      "name": "CVE-2026-50171",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50171"
    },
    {
      "name": "CVE-2026-45447",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45447"
    },
    {
      "name": "CVE-2026-22731",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22731"
    },
    {
      "name": "CVE-2026-41843",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41843"
    },
    {
      "name": "CVE-2026-22732",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22732"
    },
    {
      "name": "CVE-2026-40181",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40181"
    },
    {
      "name": "CVE-2026-54274",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54274"
    },
    {
      "name": "CVE-2026-34487",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34487"
    },
    {
      "name": "CVE-2026-54512",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54512"
    },
    {
      "name": "CVE-2026-41850",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41850"
    },
    {
      "name": "CVE-2026-34197",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34197"
    },
    {
      "name": "CVE-2026-33244",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33244"
    },
    {
      "name": "CVE-2026-54266",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54266"
    },
    {
      "name": "CVE-2026-45446",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45446"
    },
    {
      "name": "CVE-2026-40198",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40198"
    },
    {
      "name": "CVE-2026-53537",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53537"
    },
    {
      "name": "CVE-2026-4176",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4176"
    },
    {
      "name": "CVE-2026-48524",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48524"
    },
    {
      "name": "CVE-2026-40046",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40046"
    },
    {
      "name": "CVE-2026-52725",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52725"
    },
    {
      "name": "CVE-2026-54273",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54273"
    },
    {
      "name": "CVE-2025-64775",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-64775"
    },
    {
      "name": "CVE-2026-41852",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41852"
    },
    {
      "name": "CVE-2026-27830",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27830"
    },
    {
      "name": "CVE-2026-11897",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11897"
    },
    {
      "name": "CVE-2026-25854",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25854"
    },
    {
      "name": "CVE-2026-54531",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54531"
    },
    {
      "name": "CVE-2026-48155",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48155"
    },
    {
      "name": "CVE-2026-41851",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41851"
    },
    {
      "name": "CVE-2026-50010",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50010"
    },
    {
      "name": "CVE-2026-54279",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54279"
    },
    {
      "name": "CVE-2026-42767",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42767"
    },
    {
      "name": "CVE-2026-3381",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3381"
    },
    {
      "name": "CVE-2026-22733",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22733"
    },
    {
      "name": "CVE-2026-41841",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41841"
    },
    {
      "name": "CVE-2026-39304",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39304"
    },
    {
      "name": "CVE-2026-54517",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54517"
    },
    {
      "name": "CVE-2026-50170",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50170"
    },
    {
      "name": "CVE-2026-41846",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41846"
    },
    {
      "name": "CVE-2026-40199",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40199"
    },
    {
      "name": "CVE-2026-54513",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54513"
    },
    {
      "name": "CVE-2026-54518",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54518"
    },
    {
      "name": "CVE-2026-54276",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54276"
    },
    {
      "name": "CVE-2025-66566",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-66566"
    },
    {
      "name": "CVE-2025-66168",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-66168"
    },
    {
      "name": "CVE-2026-42342",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42342"
    },
    {
      "name": "CVE-2026-12143",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12143"
    },
    {
      "name": "CVE-2026-48523",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48523"
    },
    {
      "name": "CVE-2024-3651",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-3651"
    },
    {
      "name": "CVE-2025-66675",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-66675"
    },
    {
      "name": "CVE-2026-33227",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33227"
    },
    {
      "name": "CVE-2026-34483",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34483"
    },
    {
      "name": "CVE-2026-34182",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34182"
    },
    {
      "name": "CVE-2026-0636",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0636"
    },
    {
      "name": "CVE-2026-47691",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47691"
    },
    {
      "name": "CVE-2026-24880",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24880"
    },
    {
      "name": "CVE-2026-48525",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48525"
    },
    {
      "name": "CVE-2026-2004",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2004"
    },
    {
      "name": "CVE-2026-9071",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9071"
    },
    {
      "name": "CVE-2026-35554",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35554"
    },
    {
      "name": "CVE-2026-34993",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34993"
    },
    {
      "name": "CVE-2026-27727",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27727"
    },
    {
      "name": "CVE-2026-10852",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10852"
    },
    {
      "name": "CVE-2025-12183",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-12183"
    },
    {
      "name": "CVE-2026-41848",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41848"
    },
    {
      "name": "CVE-2025-14813",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-14813"
    },
    {
      "name": "CVE-2026-48156",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48156"
    },
    {
      "name": "CVE-2026-24281",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24281"
    },
    {
      "name": "CVE-2026-34077",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34077"
    },
    {
      "name": "CVE-2026-53539",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53539"
    },
    {
      "name": "CVE-2025-11226",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-11226"
    }
  ],
  "initial_release_date": "2026-07-24T00:00:00",
  "last_revision_date": "2026-07-24T00:00:00",
  "links": [],
  "reference": "CERTFR-2026-AVI-0933",
  "revisions": [
    {
      "description": "Version initiale",
      "revision_date": "2026-07-24T00:00:00.000000"
    }
  ],
  "risks": [
    {
      "description": "D\u00e9ni de service \u00e0 distance"
    },
    {
      "description": "Injection de code indirecte \u00e0 distance (XSS)"
    },
    {
      "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
    },
    {
      "description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
    },
    {
      "description": "Non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur"
    },
    {
      "description": "Falsification de requ\u00eates c\u00f4t\u00e9 serveur (SSRF)"
    },
    {
      "description": "Contournement de la politique de s\u00e9curit\u00e9"
    },
    {
      "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
    },
    {
      "description": "\u00c9l\u00e9vation de privil\u00e8ges"
    }
  ],
  "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits IBM. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire \u00e0 distance, une \u00e9l\u00e9vation de privil\u00e8ges et un d\u00e9ni de service \u00e0 distance.",
  "title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits IBM",
  "vendor_advisories": [
    {
      "published_at": "2026-07-22",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7280728",
      "url": "https://www.ibm.com/support/pages/node/7280728"
    },
    {
      "published_at": "2026-07-22",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7280784",
      "url": "https://www.ibm.com/support/pages/node/7280784"
    },
    {
      "published_at": "2026-07-21",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7280667",
      "url": "https://www.ibm.com/support/pages/node/7280667"
    },
    {
      "published_at": "2026-07-21",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7280663",
      "url": "https://www.ibm.com/support/pages/node/7280663"
    },
    {
      "published_at": "2026-07-23",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7280907",
      "url": "https://www.ibm.com/support/pages/node/7280907"
    },
    {
      "published_at": "2026-07-22",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7280731",
      "url": "https://www.ibm.com/support/pages/node/7280731"
    },
    {
      "published_at": "2026-07-22",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7280720",
      "url": "https://www.ibm.com/support/pages/node/7280720"
    },
    {
      "published_at": "2026-07-24",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7281073",
      "url": "https://www.ibm.com/support/pages/node/7281073"
    },
    {
      "published_at": "2026-07-20",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7280519",
      "url": "https://www.ibm.com/support/pages/node/7280519"
    },
    {
      "published_at": "2026-07-20",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7280540",
      "url": "https://www.ibm.com/support/pages/node/7280540"
    },
    {
      "published_at": "2026-07-22",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7280730",
      "url": "https://www.ibm.com/support/pages/node/7280730"
    },
    {
      "published_at": "2026-07-22",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7280726",
      "url": "https://www.ibm.com/support/pages/node/7280726"
    },
    {
      "published_at": "2026-07-22",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7280783",
      "url": "https://www.ibm.com/support/pages/node/7280783"
    },
    {
      "published_at": "2026-07-21",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7280650",
      "url": "https://www.ibm.com/support/pages/node/7280650"
    },
    {
      "published_at": "2026-07-21",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7280654",
      "url": "https://www.ibm.com/support/pages/node/7280654"
    },
    {
      "published_at": "2026-07-21",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7280644",
      "url": "https://www.ibm.com/support/pages/node/7280644"
    },
    {
      "published_at": "2026-07-22",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7280729",
      "url": "https://www.ibm.com/support/pages/node/7280729"
    },
    {
      "published_at": "2026-07-22",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7280785",
      "url": "https://www.ibm.com/support/pages/node/7280785"
    },
    {
      "published_at": "2026-07-21",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7280695",
      "url": "https://www.ibm.com/support/pages/node/7280695"
    },
    {
      "published_at": "2026-07-22",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7280719",
      "url": "https://www.ibm.com/support/pages/node/7280719"
    },
    {
      "published_at": "2026-07-22",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7280727",
      "url": "https://www.ibm.com/support/pages/node/7280727"
    },
    {
      "published_at": "2026-07-21",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7280646",
      "url": "https://www.ibm.com/support/pages/node/7280646"
    },
    {
      "published_at": "2026-07-22",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7280670",
      "url": "https://www.ibm.com/support/pages/node/7280670"
    },
    {
      "published_at": "2026-07-23",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7280916",
      "url": "https://www.ibm.com/support/pages/node/7280916"
    },
    {
      "published_at": "2026-07-23",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7280950",
      "url": "https://www.ibm.com/support/pages/node/7280950"
    },
    {
      "published_at": "2026-07-21",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7280126",
      "url": "https://www.ibm.com/support/pages/node/7280126"
    },
    {
      "published_at": "2026-07-21",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7280656",
      "url": "https://www.ibm.com/support/pages/node/7280656"
    },
    {
      "published_at": "2026-07-22",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7280621",
      "url": "https://www.ibm.com/support/pages/node/7280621"
    },
    {
      "published_at": "2026-07-23",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7280887",
      "url": "https://www.ibm.com/support/pages/node/7280887"
    }
  ]
}

CERTFR-2026-AVI-0224
Vulnerability from certfr_avis

De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données.

Solutions

Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

IBM indique les versions correctives 9.0.5.27 et 26.0.0.3 pour WebSphere Application Server seront disponibles au cours du premier trimestre 2026. La version 8.5.5.30 sera disponible au troisième trimestre 2026.

Impacted products
Vendor Product Description
IBM WebSphere WebSphere Application Server versions 8.x antérieures à 8.5.5.30
IBM WebSphere WebSphere Application Server - Liberty versions antérieures à 26.0.0.3
IBM QRadar Assistant QRadar AI Assistant versions antérieures à 1.3.1
IBM Sterling Sterling Secure Proxy versions 6.1.x antérieures à 6.1.0.3 GA
IBM QRadar QRadar SIEM versions 7.5.x antérieures à 7.5.0 UP14 IF05
IBM Sterling Sterling Transformation Extender sans l'application des mesures de contournement décrites par l'éditeur
IBM Sterling Sterling Secure Proxy versions 6.2.1.x antérieures à 6.2.1.1 GA
IBM Db2 Db2 mirror pour i sans les derniers correctifs de sécurité
IBM WebSphere WebSphere Application Server versions 9.x antérieures à 9.0.5.27
IBM Sterling Sterling Secure Proxy versions 6.2.x antérieures à 6.2.0.3 GA
IBM Cognos Command Center Cognos Command Center versions antérieures à 10.2.5 FP1 IF3
References
Bulletin de sécurité IBM 7261959 2026-02-26 vendor-advisory
Bulletin de sécurité IBM 7261794 2026-02-25 vendor-advisory
Bulletin de sécurité IBM 7261890 2026-02-25 vendor-advisory
Bulletin de sécurité IBM 7261887 2026-02-25 vendor-advisory
Bulletin de sécurité IBM 7261935 2026-02-26 vendor-advisory
Bulletin de sécurité IBM 7261436 2026-02-20 vendor-advisory
Bulletin de sécurité IBM 7261774 2026-02-25 vendor-advisory

Show details on source website


{
  "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
  "affected_systems": [
    {
      "description": "WebSphere Application Server versions 8.x ant\u00e9rieures \u00e0 8.5.5.30",
      "product": {
        "name": "WebSphere",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "WebSphere Application Server - Liberty versions ant\u00e9rieures \u00e0 26.0.0.3",
      "product": {
        "name": "WebSphere",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "QRadar AI Assistant versions ant\u00e9rieures \u00e0 1.3.1",
      "product": {
        "name": "QRadar Assistant",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Sterling Secure Proxy versions 6.1.x ant\u00e9rieures \u00e0 6.1.0.3 GA",
      "product": {
        "name": "Sterling",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "QRadar SIEM versions 7.5.x ant\u00e9rieures \u00e0 7.5.0 UP14 IF05",
      "product": {
        "name": "QRadar",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Sterling Transformation Extender sans l\u0027application des mesures de contournement d\u00e9crites par l\u0027\u00e9diteur",
      "product": {
        "name": "Sterling",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Sterling Secure Proxy versions 6.2.1.x ant\u00e9rieures \u00e0 6.2.1.1 GA",
      "product": {
        "name": "Sterling",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Db2 mirror pour i sans les derniers correctifs de s\u00e9curit\u00e9",
      "product": {
        "name": "Db2",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "WebSphere Application Server versions 9.x ant\u00e9rieures \u00e0 9.0.5.27",
      "product": {
        "name": "WebSphere",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Sterling Secure Proxy versions 6.2.x ant\u00e9rieures \u00e0 6.2.0.3 GA",
      "product": {
        "name": "Sterling",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Cognos Command Center versions ant\u00e9rieures \u00e0 10.2.5 FP1 IF3",
      "product": {
        "name": "Cognos Command Center",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    }
  ],
  "affected_systems_content": "IBM indique les versions correctives 9.0.5.27 et 26.0.0.3 pour WebSphere Application Server seront disponibles au cours du premier trimestre 2026. La version 8.5.5.30 sera disponible au troisi\u00e8me trimestre 2026.",
  "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
  "cves": [
    {
      "name": "CVE-2026-21933",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21933"
    },
    {
      "name": "CVE-2026-21932",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21932"
    },
    {
      "name": "CVE-2025-12816",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-12816"
    },
    {
      "name": "CVE-2025-68973",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-68973"
    },
    {
      "name": "CVE-2025-65106",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-65106"
    },
    {
      "name": "CVE-2026-22610",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22610"
    },
    {
      "name": "CVE-2025-66412",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-66412"
    },
    {
      "name": "CVE-2025-40240",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-40240"
    },
    {
      "name": "CVE-2025-69223",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69223"
    },
    {
      "name": "CVE-2025-66035",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-66035"
    },
    {
      "name": "CVE-2025-68664",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-68664"
    },
    {
      "name": "CVE-2026-22701",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22701"
    },
    {
      "name": "CVE-2026-23745",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23745"
    },
    {
      "name": "CVE-2026-22690",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22690"
    },
    {
      "name": "CVE-2025-15284",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15284"
    },
    {
      "name": "CVE-2025-69230",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69230"
    },
    {
      "name": "CVE-2025-66019",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-66019"
    },
    {
      "name": "CVE-2026-21925",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21925"
    },
    {
      "name": "CVE-2025-66031",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-66031"
    },
    {
      "name": "CVE-2025-69225",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69225"
    },
    {
      "name": "CVE-2026-21860",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21860"
    },
    {
      "name": "CVE-2025-40277",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-40277"
    },
    {
      "name": "CVE-2023-53673",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-53673"
    },
    {
      "name": "CVE-2026-1615",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1615"
    },
    {
      "name": "CVE-2025-69227",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69227"
    },
    {
      "name": "CVE-2026-1188",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1188"
    },
    {
      "name": "CVE-2025-66471",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-66471"
    },
    {
      "name": "CVE-2025-68146",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-68146"
    },
    {
      "name": "CVE-2025-66030",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-66030"
    },
    {
      "name": "CVE-2025-61140",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-61140"
    },
    {
      "name": "CVE-2025-66221",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-66221"
    },
    {
      "name": "CVE-2025-69228",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69228"
    },
    {
      "name": "CVE-2025-39993",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-39993"
    },
    {
      "name": "CVE-2024-29371",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-29371"
    },
    {
      "name": "CVE-2025-40154",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-40154"
    },
    {
      "name": "CVE-2025-13601",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-13601"
    },
    {
      "name": "CVE-2025-69226",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69226"
    },
    {
      "name": "CVE-2026-21945",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21945"
    },
    {
      "name": "CVE-2025-40248",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-40248"
    },
    {
      "name": "CVE-2025-9230",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-9230"
    },
    {
      "name": "CVE-2025-69224",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69224"
    },
    {
      "name": "CVE-2025-64756",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-64756"
    },
    {
      "name": "CVE-2025-69229",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69229"
    },
    {
      "name": "CVE-2025-68480",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-68480"
    },
    {
      "name": "CVE-2025-14847",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-14847"
    },
    {
      "name": "CVE-2025-68285",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-68285"
    },
    {
      "name": "CVE-2025-68615",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-68615"
    },
    {
      "name": "CVE-2026-22691",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22691"
    },
    {
      "name": "CVE-2025-66418",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-66418"
    }
  ],
  "initial_release_date": "2026-02-27T00:00:00",
  "last_revision_date": "2026-02-27T00:00:00",
  "links": [],
  "reference": "CERTFR-2026-AVI-0224",
  "revisions": [
    {
      "description": "Version initiale",
      "revision_date": "2026-02-27T00:00:00.000000"
    }
  ],
  "risks": [
    {
      "description": "D\u00e9ni de service \u00e0 distance"
    },
    {
      "description": "Injection de code indirecte \u00e0 distance (XSS)"
    },
    {
      "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
    },
    {
      "description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
    },
    {
      "description": "Contournement de la politique de s\u00e9curit\u00e9"
    },
    {
      "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
    }
  ],
  "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits IBM. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire \u00e0 distance, un d\u00e9ni de service \u00e0 distance et une atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es.",
  "title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits IBM",
  "vendor_advisories": [
    {
      "published_at": "2026-02-26",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7261959",
      "url": "https://www.ibm.com/support/pages/node/7261959"
    },
    {
      "published_at": "2026-02-25",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7261794",
      "url": "https://www.ibm.com/support/pages/node/7261794"
    },
    {
      "published_at": "2026-02-25",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7261890",
      "url": "https://www.ibm.com/support/pages/node/7261890"
    },
    {
      "published_at": "2026-02-25",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7261887",
      "url": "https://www.ibm.com/support/pages/node/7261887"
    },
    {
      "published_at": "2026-02-26",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7261935",
      "url": "https://www.ibm.com/support/pages/node/7261935"
    },
    {
      "published_at": "2026-02-20",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7261436",
      "url": "https://www.ibm.com/support/pages/node/7261436"
    },
    {
      "published_at": "2026-02-25",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7261774",
      "url": "https://www.ibm.com/support/pages/node/7261774"
    }
  ]
}

CVE-2025-1994 (GCVE-0-2025-1994)
Vulnerability from cvelistv5
Published
2025-08-26 16:49
Modified
2025-08-26 17:35
CWE
  • CWE-242 - Use of Inherently Dangerous Function
Summary
IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a local user to execute arbitrary code on the system due to the use of unsafe use of the BinaryFormatter function.
References
Impacted products
Vendor Product Version
IBM Cognos Command Center Version: 10.2.4.1
Version: 10.2.5
    cpe:2.3:a:ibm:cognos_command_center:10.2.4.1:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:cognos_command_center:10.2.5:*:*:*:*:*:*:*
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2025-1994",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2025-08-26T17:35:43.289596Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2025-08-26T17:35:50.942Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:ibm:cognos_command_center:10.2.4.1:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:cognos_command_center:10.2.5:*:*:*:*:*:*:*"
          ],
          "defaultStatus": "unaffected",
          "product": "Cognos Command Center",
          "vendor": "IBM",
          "versions": [
            {
              "status": "affected",
              "version": "10.2.4.1"
            },
            {
              "status": "affected",
              "version": "10.2.5"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "IBM Cognos Command Center 10.2.4.1 and 10.2.5 \n\n\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\n\n\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003ecould allow a local user to execute arbitrary code on the system due to the use of unsafe use of the BinaryFormatter function.\u003c/span\u003e\n\n\u003c/span\u003e"
            }
          ],
          "value": "IBM Cognos Command Center 10.2.4.1 and 10.2.5 \n\n\n\ncould allow a local user to execute arbitrary code on the system due to the use of unsafe use of the BinaryFormatter function."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-242",
              "description": "CWE-242 Use of Inherently Dangerous Function",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2025-08-26T16:49:03.832Z",
        "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "shortName": "ibm"
      },
      "references": [
        {
          "tags": [
            "vendor-advisory",
            "patch"
          ],
          "url": "https://www.ibm.com/support/pages/node/7242159"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eIBM strongly recommends addressing the vulnerability now by upgrading.\u003c/p\u003e\u003cdiv\u003e\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003eAffected Product(s)\u003c/td\u003e\u003ctd\u003eVersion\u003c/td\u003e\u003ctd\u003eFix\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eIBM Cognos Command Center\u003c/td\u003e\u003ctd\u003e10.2.5\u003c/td\u003e\u003ctd\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\u003ca target=\"_blank\" rel=\"nofollow\" href=\"https://www.ibm.com/support/pages/node/7239167\"\u003eIBM Cognos Command Center 10.2.5 FP1 IF1 available for download from Fix Central\u003c/a\u003e\u003c/span\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eIBM Cognos Command Center\u003c/td\u003e\u003ctd\u003e10.2.4.1\u003c/td\u003e\u003ctd\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\u003ca target=\"_blank\" rel=\"nofollow\" href=\"https://www.ibm.com/support/pages/node/7239167\"\u003eIBM Cognos Command Center 10.2.5 FP1 IF1 available for download from Fix Central\u003c/a\u003e\u003c/span\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\n\n\u003cbr\u003e"
            }
          ],
          "value": "IBM strongly recommends addressing the vulnerability now by upgrading.\n\nAffected Product(s)VersionFixIBM Cognos Command Center10.2.5 IBM Cognos Command Center 10.2.5 FP1 IF1 available for download from Fix Central https://www.ibm.com/support/pages/node/7239167 IBM Cognos Command Center10.2.4.1 IBM Cognos Command Center 10.2.5 FP1 IF1 available for download from Fix Central https://www.ibm.com/support/pages/node/7239167"
        }
      ],
      "source": {
        "discovery": "UNKNOWN"
      },
      "title": "IBM Cognos Command Center code execution",
      "x_generator": {
        "engine": "Vulnogram 0.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
    "assignerShortName": "ibm",
    "cveId": "CVE-2025-1994",
    "datePublished": "2025-08-26T16:49:03.832Z",
    "dateReserved": "2025-03-05T16:10:32.378Z",
    "dateUpdated": "2025-08-26T17:35:50.942Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}

CVE-2025-2697 (GCVE-0-2025-2697)
Vulnerability from cvelistv5
Published
2025-08-26 16:47
Modified
2025-08-26 17:36
CWE
  • CWE-601 - URL Redirection to Untrusted Site ('Open Redirect')
Summary
IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.
References
Impacted products
Vendor Product Version
IBM Cognos Command Center Version: 10.2.4.1
Version: 10.2.5
    cpe:2.3:a:ibm:cognos_command_center:10.2.4.1:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:cognos_command_center:10.2.5:*:*:*:*:*:*:*
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2025-2697",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2025-08-26T17:36:02.720697Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2025-08-26T17:36:08.348Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:ibm:cognos_command_center:10.2.4.1:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:cognos_command_center:10.2.5:*:*:*:*:*:*:*"
          ],
          "defaultStatus": "unaffected",
          "product": "Cognos Command Center",
          "vendor": "IBM",
          "versions": [
            {
              "status": "affected",
              "version": "10.2.4.1"
            },
            {
              "status": "affected",
              "version": "10.2.5"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "IBM Cognos Command Center 10.2.4.1 and 10.2.5 \n\n\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003ecould allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.\u003c/span\u003e"
            }
          ],
          "value": "IBM Cognos Command Center 10.2.4.1 and 10.2.5 \n\ncould allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 7.4,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-601",
              "description": "CWE-601 URL Redirection to Untrusted Site (\u0027Open Redirect\u0027)",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2025-08-26T16:47:25.981Z",
        "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "shortName": "ibm"
      },
      "references": [
        {
          "tags": [
            "vendor-advisory",
            "patch"
          ],
          "url": "https://www.ibm.com/support/pages/node/7242159"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eIBM strongly recommends addressing the vulnerability now by upgrading.\u003c/p\u003e\u003cdiv\u003e\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003eAffected Product(s)\u003c/td\u003e\u003ctd\u003eVersion\u003c/td\u003e\u003ctd\u003eFix\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eIBM Cognos Command Center\u003c/td\u003e\u003ctd\u003e10.2.5\u003c/td\u003e\u003ctd\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\u003ca target=\"_blank\" rel=\"nofollow\" href=\"https://www.ibm.com/support/pages/node/7239167\"\u003eIBM Cognos Command Center 10.2.5 FP1 IF1 available for download from Fix Central\u003c/a\u003e\u003c/span\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eIBM Cognos Command Center\u003c/td\u003e\u003ctd\u003e10.2.4.1\u003c/td\u003e\u003ctd\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\u003ca target=\"_blank\" rel=\"nofollow\" href=\"https://www.ibm.com/support/pages/node/7239167\"\u003eIBM Cognos Command Center 10.2.5 FP1 IF1 available for download from Fix Central\u003c/a\u003e\u003c/span\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\n\n\u003cbr\u003e"
            }
          ],
          "value": "IBM strongly recommends addressing the vulnerability now by upgrading.\n\nAffected Product(s)VersionFixIBM Cognos Command Center10.2.5 IBM Cognos Command Center 10.2.5 FP1 IF1 available for download from Fix Central https://www.ibm.com/support/pages/node/7239167 IBM Cognos Command Center10.2.4.1 IBM Cognos Command Center 10.2.5 FP1 IF1 available for download from Fix Central https://www.ibm.com/support/pages/node/7239167"
        }
      ],
      "source": {
        "discovery": "UNKNOWN"
      },
      "title": "IBM Cognos Command Center HTTP Open Redirect",
      "x_generator": {
        "engine": "Vulnogram 0.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
    "assignerShortName": "ibm",
    "cveId": "CVE-2025-2697",
    "datePublished": "2025-08-26T16:47:25.981Z",
    "dateReserved": "2025-03-23T16:28:25.483Z",
    "dateUpdated": "2025-08-26T17:36:08.348Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}

CVE-2025-1494 (GCVE-0-2025-1494)
Vulnerability from cvelistv5
Published
2025-08-26 16:45
Modified
2025-08-26 17:36
CWE
  • CWE-1021 - Improper Restriction of Rendered UI Layers or Frames
Summary
IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim.
References
Impacted products
Vendor Product Version
IBM Cognos Command Center Version: 10.2.4.1
Version: 10.2.5
    cpe:2.3:a:ibm:cognos_command_center:10.2.4.1:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:cognos_command_center:10.2.5:*:*:*:*:*:*:*
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2025-1494",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2025-08-26T17:36:21.928358Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2025-08-26T17:36:26.140Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:ibm:cognos_command_center:10.2.4.1:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:cognos_command_center:10.2.5:*:*:*:*:*:*:*"
          ],
          "defaultStatus": "unaffected",
          "product": "Cognos Command Center",
          "vendor": "IBM",
          "versions": [
            {
              "status": "affected",
              "version": "10.2.4.1"
            },
            {
              "status": "affected",
              "version": "10.2.5"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim\u0027s click actions and possibly launch further attacks against the victim."
            }
          ],
          "value": "IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim\u0027s click actions and possibly launch further attacks against the victim."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-1021",
              "description": "CWE-1021 Improper Restriction of Rendered UI Layers or Frames",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2025-08-26T16:45:35.076Z",
        "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "shortName": "ibm"
      },
      "references": [
        {
          "tags": [
            "vendor-advisory",
            "patch"
          ],
          "url": "https://www.ibm.com/support/pages/node/7242159"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eIBM strongly recommends addressing the vulnerability now by upgrading.\u003c/p\u003e\u003cdiv\u003e\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003eAffected Product(s)\u003c/td\u003e\u003ctd\u003eVersion\u003c/td\u003e\u003ctd\u003eFix\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eIBM Cognos Command Center\u003c/td\u003e\u003ctd\u003e10.2.5\u003c/td\u003e\u003ctd\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\u003ca target=\"_blank\" rel=\"nofollow\" href=\"https://www.ibm.com/support/pages/node/7239167\"\u003eIBM Cognos Command Center 10.2.5 FP1 IF1 available for download from Fix Central\u003c/a\u003e\u003c/span\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eIBM Cognos Command Center\u003c/td\u003e\u003ctd\u003e10.2.4.1\u003c/td\u003e\u003ctd\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\u003ca target=\"_blank\" rel=\"nofollow\" href=\"https://www.ibm.com/support/pages/node/7239167\"\u003eIBM Cognos Command Center 10.2.5 FP1 IF1 available for download from Fix Central\u003c/a\u003e\u003c/span\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\n\n\u003cbr\u003e"
            }
          ],
          "value": "IBM strongly recommends addressing the vulnerability now by upgrading.\n\nAffected Product(s)VersionFixIBM Cognos Command Center10.2.5 IBM Cognos Command Center 10.2.5 FP1 IF1 available for download from Fix Central https://www.ibm.com/support/pages/node/7239167 IBM Cognos Command Center10.2.4.1 IBM Cognos Command Center 10.2.5 FP1 IF1 available for download from Fix Central https://www.ibm.com/support/pages/node/7239167"
        }
      ],
      "source": {
        "discovery": "UNKNOWN"
      },
      "title": "IBM Cognos Command Center clickjacking",
      "x_generator": {
        "engine": "Vulnogram 0.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
    "assignerShortName": "ibm",
    "cveId": "CVE-2025-1494",
    "datePublished": "2025-08-26T16:45:35.076Z",
    "dateReserved": "2025-02-20T02:17:49.762Z",
    "dateUpdated": "2025-08-26T17:36:26.140Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}

CVE-2024-31899 (GCVE-0-2024-31899)
Vulnerability from cvelistv5
Published
2024-09-26 13:34
Modified
2024-09-26 17:04
CWE
  • CWE-256 - Plaintext Storage of a Password
Summary
IBM Cognos Command Center 10.2.4.1 and 10.2.5 could disclose highly sensitive user information to an authenticated user with physical access to the device.
References
Impacted products
Vendor Product Version
IBM Cognos Command Center Version: 10.2.4.1, 10.2.5
    cpe:2.3:a:ibm:cognos_command_center:10.2.5:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:cognos_command_center:10.2.4.1:*:*:*:*:*:*:*
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2024-31899",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-09-26T17:03:17.985272Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-09-26T17:04:12.761Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:ibm:cognos_command_center:10.2.5:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:cognos_command_center:10.2.4.1:*:*:*:*:*:*:*"
          ],
          "defaultStatus": "unaffected",
          "product": "Cognos Command Center",
          "vendor": "IBM",
          "versions": [
            {
              "status": "affected",
              "version": "10.2.4.1, 10.2.5"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "IBM Cognos Command Center 10.2.4.1 and 10.2.5 could disclose highly sensitive user information to an authenticated user with physical access to the device."
            }
          ],
          "value": "IBM Cognos Command Center 10.2.4.1 and 10.2.5 could disclose highly sensitive user information to an authenticated user with physical access to the device."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "PHYSICAL",
            "availabilityImpact": "NONE",
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-256",
              "description": "CWE-256 Plaintext Storage of a Password",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2024-09-26T13:34:57.008Z",
        "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "shortName": "ibm"
      },
      "references": [
        {
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://www.ibm.com/support/pages/node/7149734"
        }
      ],
      "source": {
        "discovery": "UNKNOWN"
      },
      "title": "IBM Cognos Command Center information disclosure",
      "x_generator": {
        "engine": "Vulnogram 0.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
    "assignerShortName": "ibm",
    "cveId": "CVE-2024-31899",
    "datePublished": "2024-09-26T13:34:57.008Z",
    "dateReserved": "2024-04-07T12:44:57.197Z",
    "dateUpdated": "2024-09-26T17:04:12.761Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}

CVE-2023-50324 (GCVE-0-2023-50324)
Vulnerability from cvelistv5
Published
2024-03-01 01:58
Modified
2024-08-02 22:16
CWE
  • CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor
Summary
IBM Cognos Command Center 10.2.4.1 and 10.2.5 exposes details the X-AspNet-Version Response Header that could allow an attacker to obtain information of the application environment to conduct further attacks. IBM X-Force ID: 275038.
Impacted products
Vendor Product Version
IBM Cognos Command Center Version: 10.2.4.1, 10.2.5
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "affected": [
          {
            "cpes": [
              "cpe:2.3:a:ibm:cognos_command_center:10.2.5:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unaffected",
            "product": "cognos_command_center",
            "vendor": "ibm",
            "versions": [
              {
                "status": "affected",
                "version": "10.2.5"
              }
            ]
          },
          {
            "cpes": [
              "cpe:2.3:a:ibm:cognos_command_center:10.2.4.1:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unaffected",
            "product": "cognos_command_center",
            "vendor": "ibm",
            "versions": [
              {
                "status": "affected",
                "version": "10.2.4.1"
              }
            ]
          }
        ],
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2023-50324",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-03-04T20:37:18.671543Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-07-12T22:02:55.939Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      },
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-02T22:16:46.252Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "vendor-advisory",
              "x_transferred"
            ],
            "url": "https://www.ibm.com/support/pages/node/7112504"
          },
          {
            "tags": [
              "vdb-entry",
              "x_transferred"
            ],
            "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/275038"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Cognos Command Center",
          "vendor": "IBM",
          "versions": [
            {
              "status": "affected",
              "version": "10.2.4.1, 10.2.5"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "IBM Cognos Command Center 10.2.4.1 and 10.2.5 exposes details the X-AspNet-Version Response Header that could allow an attacker to obtain information of the application environment to conduct further attacks.  IBM X-Force ID:  275038."
            }
          ],
          "value": "IBM Cognos Command Center 10.2.4.1 and 10.2.5 exposes details the X-AspNet-Version Response Header that could allow an attacker to obtain information of the application environment to conduct further attacks.  IBM X-Force ID:  275038."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-200",
              "description": "CWE-200 Exposure of Sensitive Information to an Unauthorized Actor",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2024-03-01T01:58:09.921Z",
        "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "shortName": "ibm"
      },
      "references": [
        {
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://www.ibm.com/support/pages/node/7112504"
        },
        {
          "tags": [
            "vdb-entry"
          ],
          "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/275038"
        }
      ],
      "source": {
        "discovery": "UNKNOWN"
      },
      "title": "IBM Cognos Command Center information disclosure",
      "x_generator": {
        "engine": "Vulnogram 0.1.0-dev"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
    "assignerShortName": "ibm",
    "cveId": "CVE-2023-50324",
    "datePublished": "2024-03-01T01:58:09.921Z",
    "dateReserved": "2023-12-07T01:29:21.981Z",
    "dateUpdated": "2024-08-02T22:16:46.252Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}

CVE-2022-38707 (GCVE-0-2022-38707)
Vulnerability from cvelistv5
Published
2023-05-05 13:54
Modified
2025-01-29 16:56
CWE
  • CWE-613 - Insufficient Session Expiration
Summary
IBM Cognos Command Center 10.2.4.1 could allow a local attacker to obtain sensitive information due to insufficient session expiration. IBM X-Force ID: 234179.
Impacted products
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-03T11:02:14.515Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "vendor-advisory",
              "x_transferred"
            ],
            "url": "https://www.ibm.com/support/pages/node/6983274"
          },
          {
            "tags": [
              "vdb-entry",
              "x_transferred"
            ],
            "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/234179"
          }
        ],
        "title": "CVE Program Container"
      },
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2022-38707",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2025-01-29T16:55:58.091573Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2025-01-29T16:56:04.168Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Cognos Command Center",
          "vendor": "IBM",
          "versions": [
            {
              "status": "affected",
              "version": "10.2.4.1"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "IBM Cognos Command Center 10.2.4.1 could allow a local attacker to obtain sensitive information due to insufficient session expiration.  IBM X-Force ID:  234179."
            }
          ],
          "value": "IBM Cognos Command Center 10.2.4.1 could allow a local attacker to obtain sensitive information due to insufficient session expiration.  IBM X-Force ID:  234179."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "NONE",
            "baseScore": 4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-613",
              "description": "CWE-613 Insufficient Session Expiration",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2023-05-05T13:54:45.562Z",
        "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "shortName": "ibm"
      },
      "references": [
        {
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://www.ibm.com/support/pages/node/6983274"
        },
        {
          "tags": [
            "vdb-entry"
          ],
          "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/234179"
        }
      ],
      "source": {
        "discovery": "UNKNOWN"
      },
      "title": "IBM Cognos Command Center information disclosure",
      "x_generator": {
        "engine": "Vulnogram 0.1.0-dev"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
    "assignerShortName": "ibm",
    "cveId": "CVE-2022-38707",
    "datePublished": "2023-05-05T13:54:45.562Z",
    "dateReserved": "2022-08-23T16:35:16.509Z",
    "dateUpdated": "2025-01-29T16:56:04.168Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}