Security Risk in IBM Cognos Analytics Enables Malicious File Uploads

Security Risk in IBM Cognos Analytics Enables Malicious File Uploads

Severe Security Flaws Discovered in IBM Cognos Analytics: Immediate Action Required

IBM has disclosed two critical vulnerabilities impacting its Cognos Analytics software, exposing systems to potential compromise through malicious file uploads and code execution. These flaws—catalogued as CVE-2024-40695 and CVE-2024-51466—span several versions of the platform and demand urgent patching to mitigate serious risk.

Flaw #1: Dangerous File Upload Capability (CVE-2024-40695)

A major threat arises from improper file validation in the Cognos Analytics web interface, enabling attackers with privileged access to upload harmful executables. Rated 8.0 on the CVSS scale, this issue (classified under CWE-434) may allow malicious payloads to be embedded directly into the system, which can then be used to launch secondary attacks on targeted users.

Due to the platform’s failure to restrict file types adequately, the risk of auto-execution of embedded code poses a significant security concern, especially in enterprise environments where user trust is leveraged.

This flaw is defined by the CVSS vector:
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H, reflecting high-impact potential through remote exploitation over a network.

Flaw #2: Remote Code Execution via Expression Language Injection (CVE-2024-51466)

Even more critical is an Expression Language (EL) injection vulnerability, earning a CVSS score of 9.0 and categorized under CWE-917. Attackers can manipulate EL statements to run unauthorized code on backend systems—no credentials or user interaction required.

This vulnerability permits remote actors to extract confidential data, destabilize system memory, or even crash the server using specially formed input. The flaw was responsibly reported by Vivek Singh of eClinicalWorks’ Application Security Team.


IBM strongly advises all organizations using Cognos Analytics to apply the provided security updates without delay. Left unpatched, these vulnerabilities could be leveraged to compromise business intelligence systems and the sensitive data they process.

Summary of IBM Cognos Analytics Vulnerabilities

IdentifierImpacted VersionsDescription of RiskAttack ConditionsSeverity (CVSS 3.1)
CVE-2024-40695Versions 12.0.0–12.0.4, 11.2.0–11.2.4 FP4Allows privileged users to upload malicious files, potentially enabling code execution or chained attacksRequires authenticated user with privileges and some user interaction8.0 (High)
CVE-2024-51466Versions 12.0.0–12.0.4, 11.2.0–11.2.4 FP4Expression Language (EL) injection can lead to data leaks, denial of service, or system crashesCan be exploited remotely without authentication9.0 (Critical)

Impacted Software Versions and Urgent Patch Guidance

Recent security flaws have been identified in IBM Cognos Analytics, specifically affecting builds from 11.2.0 through 11.2.4 FP4 and 12.0.0 through 12.0.4.

IBM urges all users to take immediate corrective action, as there are currently no temporary mitigations or configuration-based fixes available. To fully neutralize the risks, organizations should follow these targeted upgrade paths:

  • Users on versions 12.0.0 to 12.0.4 should update to 12.0.4 Interim Fix 1
  • Users on versions 11.2.0 to 11.2.4 FP4 should transition to 11.2.4 FP5

To assist IT and security teams with vulnerability identification, Nessus has released plugin ID 213474, enabling efficient detection across enterprise environments.

These findings underscore the persistent security pressures on analytics platforms that serve as custodians of sensitive business data. Timely patching is not just a best practice—it’s essential. Failure to address these exposures may leave organizations vulnerable to targeted attacks, data leaks, and operational disruption.

More Articles & Posts