CVE-2025-3633
Analyzed Analyzed - Analysis Complete
Cross-Site Scripting (XSS) in IBM Cognos Analytics and Transformer

Publication date: 2026-05-27

Last updated on: 2026-06-02

Assigner: IBM Corporation

Description
IBM Cognos Analytics 11.2.0, 11.2.4, 12.0, and 12.1.0 and IBM Cognos Transformer 11.2.4, 12.0, and 12.1.0 are vulnerable to cross-site scripting (XSS). This vulnerability allows a remote attacker to inject arbitrary JavaScript code into the web user interface, which may alter the intended functionality and could lead to the disclosure of credentials within a trusted session.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-05-27
Last Modified
2026-06-02
Generated
2026-06-16
AI Q&A
2026-05-27
EPSS Evaluated
2026-06-15
NVD
EUVD
Affected Vendors & Products
Showing 21 associated CPEs
Vendor Product Version / Range
ibm cognos_analytics 11.2.4
ibm cognos_analytics 11.2.4
ibm cognos_analytics From 11.2.0 (inc) to 11.2.4 (exc)
ibm cognos_analytics 11.2.4
ibm cognos_analytics 11.2.4
ibm cognos_analytics From 12.0.0 (inc) to 12.0.4 (exc)
ibm cognos_analytics 11.2.4
ibm cognos_analytics 12.0.4
ibm cognos_analytics 11.2.4
ibm cognos_analytics 12.0.4
ibm cognos_analytics 12.0.4
ibm cognos_analytics 11.2.4
ibm cognos_analytics 11.2.4
ibm cognos_analytics 11.2.4
ibm cognos_analytics 11.2.4
ibm cognos_analytics 11.2.4
ibm cognos_analytics From 12.1.0 (inc) to 12.1.2 (exc)
ibm cognos_analytics 11.2.4
ibm cognos_transformer 11.2.4
ibm cognos_transformer 12.0
ibm cognos_transformer 12.1.0
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Compliance Impact

The vulnerability allows a remote attacker to inject arbitrary JavaScript code into the web user interface, potentially leading to the disclosure of credentials within a trusted session.

Such unauthorized disclosure of credentials and potential alteration of functionality could impact compliance with standards and regulations like GDPR and HIPAA, which require protection of personal and sensitive data.

However, the provided information does not explicitly describe the direct effects on compliance with these standards.

Executive Summary

This vulnerability affects IBM Cognos Analytics versions 11.2.0, 11.2.4, 12.0, and 12.1.0, as well as IBM Cognos Transformer versions 11.2.4, 12.0, and 12.1.0. It is a cross-site scripting (XSS) vulnerability that allows a remote attacker to inject arbitrary JavaScript code into the web user interface.

By injecting malicious JavaScript, the attacker can alter the intended functionality of the application and potentially cause the disclosure of user credentials within a trusted session.

Impact Analysis

The impact of this vulnerability includes the possibility that an attacker could execute arbitrary JavaScript code in the context of a user's session.

This could lead to unauthorized actions being performed on behalf of the user, alteration of application behavior, and the disclosure of sensitive information such as user credentials.

Mitigation Strategies

IBM advises reviewing and applying necessary remediation actions for vulnerabilities affecting IBM Cognos Analytics, including cross-site scripting issues.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-3633. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart