{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-05-12T04:47:41.058","vulnerabilities":[{"cve":{"id":"CVE-2024-52900","sourceIdentifier":"psirt@us.ibm.com","published":"2025-06-28T01:15:24.957","lastModified":"2025-07-01T18:07:20.727","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"IBM Cognos Analytics 11.2.0 through 12.2.4 Fix Pack 5 and 12.0.0 through 12.0.4 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session."},{"lang":"es","value":"IBM Cognos Analytics 11.2.0 a 12.2.4 Fix Pack 5 y 12.0.0 a 12.0.4 son vulnerables a cross-site scripting almacenado. Esta vulnerabilidad permite a los usuarios autenticados incrustar código JavaScript arbitrario en la interfaz web, alterando así la funcionalidad prevista y pudiendo provocar la divulgación de credenciales en una sesión de confianza."}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:*:*:*:*:*:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"11.2.4","matchCriteriaId":"FA7F561D-2D45-4BDB-AE84-1BD057DC9930"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:*:*:*:*:*:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"12.0.4","matchCriteriaId":"90D7AA5F-889B-4FC6-AE9D-9659FCAC13FF"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:11.2.4:-:*:*:*:*:*:*","matchCriteriaId":"A1D81212-AFFE-4A73-AAC1-E558973FC452"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:11.2.4:fixpack1:*:*:*:*:*:*","matchCriteriaId":"07DC144D-62FC-4808-A77A-642871C1F8FC"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:11.2.4:fixpack2:*:*:*:*:*:*","matchCriteriaId":"2A61B920-B490-48A8-BF00-13B8854683FD"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:11.2.4:fixpack3:*:*:*:*:*:*","matchCriteriaId":"1F65BC6D-9A9D-45B9-919B-2855586C4F1B"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:11.2.4:fixpack4:*:*:*:*:*:*","matchCriteriaId":"684FA3C7-ABEA-4CB8-8D88-4BA18F1A73FB"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:11.2.4:fixpack5:*:*:*:*:*:*","matchCriteriaId":"3372238E-BFA8-4342-A523-9DB9628D11B7"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:11.2.4:interim_fix_1:*:*:*:*:*:*","matchCriteriaId":"C0259B4F-E86A-44E5-A1FA-39A57E915822"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:11.2.4:interim_fix_2:*:*:*:*:*:*","matchCriteriaId":"CEF69734-E894-49E2-9295-03330FE19F9C"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:11.2.4:interim_fix_3:*:*:*:*:*:*","matchCriteriaId":"28C2275C-A326-4914-BD31-923E0976DA5B"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:11.2.4:interim_fix_4:*:*:*:*:*:*","matchCriteriaId":"C19D8CDA-E883-4F76-ACEE-FE16A6AB75A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:11.2.4:interim_fix_5:*:*:*:*:*:*","matchCriteriaId":"AF2CD238-A72E-4689-B8E7-2949A0E618E2"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cognos_analytics:12.0.4:-:*:*:*:*:*:*","matchCriteriaId":"CED100CC-0C88-41B9-8742-4AD51C105527"}]}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7238163","source":"psirt@us.ibm.com","tags":["Patch","Vendor Advisory"]}]}}]}