Junglewise Threat Intelligence

CVE-2025-3633: IBM Cognos Analytics cross-site scripting in web interface

CVE-2025-3633 · Severity: medium · CVSS 5.4 · Published 2026-05-27

Technologies: IBM Cognos Analytics. Vendors: IBM.

Executive brief

IBM Cognos Analytics and Transformer, which are business intelligence and data modeling tools, are affected by a security flaw that allows attackers to run malicious scripts in a user's browser. If a logged-in user interacts with a malicious link or page, an attacker could potentially steal their login credentials or perform unauthorized actions on their behalf. This could lead to unauthorized access to sensitive corporate data and reports.

Technical details

IBM Cognos Analytics and Transformer are vulnerable to a stored or reflected cross-site scripting (XSS) attack due to improper neutralization of user-supplied input during web page generation (CWE-79). A remote attacker with low privileges can exploit this by injecting arbitrary JavaScript code into the web user interface. Successful exploitation requires a victim to interact with the malicious content (User Interaction: Required). This can lead to the disclosure of sensitive session information, such as credentials or session tokens, within a trusted session, and allows the attacker to alter the intended functionality of the web interface.

Affected products

  • IBM Cognos Analytics 11.2.0, 11.2.4, 12.0, 12.1.0
  • IBM Cognos Transformer 11.2.4, 12.0, 12.1.0

Timeline

  • 2026-05-27: advisory: NVD published the CVE record based on IBM's disclosure.

References

Related threats