CVE detail
CVE-2025-3633 — CVE-2025-3633
Published 2026-05-27 · Modified 2026-06-17 · Vendor ibm · Product cognos_analytics · Source nvd
MEDIUM
severity
CVSS-derived band
0.0031
EPSS probability
exploitation probability, 30d
23.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
IBM Cognos Analytics 11.2.0, 11.2.4, 12.0, and 12.1.0 and IBM Cognos Transformer 11.2.4, 12.0, and 12.1.0 are vulnerable to cross-site scripting (XSS). This vulnerability allows a remote attacker to inject arbitrary JavaScript code into the web user interface, which may alter the intended functionality and could lead to the disclosure of credentials within a trusted session.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References