Executive brief
IBM Cognos Analytics is a business intelligence and analytics platform used by enterprises to analyze and visualize data. The product fails to properly enforce HTTP Strict Transport Security (HSTS), allowing attackers on the network path between users and the server to intercept and modify unencrypted communications. This could expose sensitive business data, user credentials, and session information to eavesdropping and man-in-the-middle attacks.
Technical details
This vulnerability is caused by the failure to properly enable HTTP Strict Transport Security (HSTS) headers in IBM Cognos Analytics. The vulnerability is classified under CWE-327 (Use of a Broken or Risky Cryptographic Algorithm) and allows remote attackers to intercept sensitive information using man-in-the-middle (MITM) techniques. The attack requires network adjacency and no authentication, but is mitigated by high complexity (AC:H). An attacker positioned on the network path can intercept HTTPS communications and extract confidential data. Fixes are available: upgrade to Cognos Analytics 12.0.4 FP3 or 12.1.3 FP2.
Affected products
- IBM Cognos Analytics 12.0.4 through 12.0.4 FP2, 12.1.0 through 12.1.3 FP1
Timeline
- 2026-09-18: disclosed