ISLAMABAD: The Pakistan Telecommunication Authority (PTA) has issued a cybersecurity advisory highlighting critical vulnerabilities in IBM Cognos Analytics. These flaws pose a serious threat, potentially allowing attackers to gain unauthorized access to systems. This warning is particularly concerning for businesses and government agencies relying on the software for data analysis and reporting, emphasizing the urgent need for security measures.
IBM® Cognos Analytics is a business intelligence solution that manages and analyses data. Users can prepare, explore, and share data using the self-service capabilities. Cognos Analytics encompasses numeric intelligence (NA) methods for prediction, description, and exploration.
Due to insufficient validation of column titles in the Cognos Assistant feature, these issues arise. An attacker could possibly cause data breaches or unauthorized acts by injecting malicious scripts into web pages viewed by other users due to XSS vulnerabilities.
There is a security hole in the IBM Planning Analytics Data Source Connection that could allow malicious actors to impersonate trusted entities, alter server traffic, and obtain sensitive data.
This issue affects the following versions of IBM Cognos Analytics:
Unauthorized access and possible data breaches are among the serious threats posed by the vulnerabilities, which fall under the CVE-2024-25041 and CVE-2024-25053 categories.
IBM’s security advice outlines patches, upgrades, and workarounds; PTA advises organizations employing affected versions of IBM Cognos Analytics to take urgent action by following this warning. To protect against known vulnerabilities, it is vital to update systems with the newest security patches regularly.
It is highly recommended that organizations keep an eye out for any suspicious activity and notify PTA through its CERT site or email in the event of any incidents.
PTA has issued this advisory as part of its continuing efforts to strengthen cybersecurity in Pakistan and safeguard vital infrastructure. Serious repercussions, such as monetary losses and reputational harm, could result from ignoring these vulnerabilities.
During a recent National Assembly Standing Committee on Information Technology meeting, Pakistan People's Party (PPP)…
Islamabad: The Pakistan Telecommunication Authority (PTA) has reported a fault in the Asia-Africa-Europe 1 (AAE-1)…
Islamabad: A Turkish consortium, the only bidder for the management of Pakistan's Islamabad airport, has…
The State Bank of Pakistan (SBP) reported a decline of over $143 million in its…
The mid-range smartphone market is set to be dominated by three key players in 2025:…
Karachi: Sindh Governor Kamran Khan Tessori has unveiled an ambitious plan to offer free modern…