Home

Description

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 could allow an authenticated user to cause a denial of service by sending a specially crafted request that would exhaust memory resources.

PUBLISHED Reserved 2025-01-31 | Published 2025-06-11 | Updated 2025-08-24 | Assigner ibm




HIGH: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Problem types

CWE-770 Allocation of Resources Without Limits or Throttling

Product status

Default status
unaffected

11.2.0
affected

11.2.1
affected

11.2.2
affected

11.2.3
affected

11.2.4
affected

12.0.0
affected

12.0.1
affected

12.0.2
affected

12.0.3
affected

12.0.4
affected

References

www.ibm.com/support/pages/node/7234674 vendor-advisory patch

cve.org (CVE-2025-25032)

nvd.nist.gov (CVE-2025-25032)

Download JSON