IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3
is potentially vulnerable to Cross Site Scripting (XSS). A remote attacker could execute malicious commands due to improper validation of column headings in Cognos Explorations.
| Software | From | Fixed in |
|---|---|---|
| ibm / cognos_analytics | 12.0.0 | 12.0.3.x |
| ibm / cognos_analytics | 11.2.0 | 11.2.4.x |