- Description
- IBM Cognos Analytics 12.1.3 GA Version with build number through 12.1.3-2606251736 could allow an attacker to obtain incorrect report summary results or cause report-processing failures due to a race condition in the Agentic AI assistant's concurrent request-handling logic when multiple authenticated users submit report-related tasks simultaneously.
- Source
- psirt@us.ibm.com
- NVD status
- Analyzed
- Products
- cognos_analytics
CVSS 3.1
- Type
- Primary
- Base score
- 4.2
- Impact score
- 2.5
- Exploitability score
- 1.6
- Vector string
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
- Severity
- MEDIUM
- psirt@us.ibm.com
- CWE-362
- Hype score
- Not currently trending
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ibm:cognos_analytics:12.1.3:2606251736:*:*:*:*:*:*",
"matchCriteriaId": "59344DCC-2ABB-4642-A303-60626D6B676D",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]