VYPR
Unrated severityNVD Advisory· Published Jan 18, 2011· Updated Apr 29, 2026

CVE-2011-0486

CVE-2011-0486

Description

Cross-site scripting (XSS) vulnerability in cognos.cgi in IBM Cognos 8 Business Intelligence (BI) 8.4.1 before FP1 allows remote attackers to inject arbitrary web script or HTML via the pathinfo parameter.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

IBM Cognos 8 BI 8.4.1 before FP1 is vulnerable to reflected XSS in cognos.cgi via the pathinfo parameter, enabling arbitrary script injection.

Vulnerability

A cross-site scripting (XSS) vulnerability exists in cognos.cgi, part of IBM Cognos 8 Business Intelligence (BI) version 8.4.1 prior to Fix Pack 1 (FP1). The flaw resides in the handling of the pathinfo parameter, which is echoed back without proper sanitization, allowing injection of arbitrary HTML and JavaScript. Affected versions are all releases of IBM Cognos 8 BI 8.4.1 before the application of FP1 [1].

Exploitation

Exploitation does not require authentication as cognos.cgi is publicly accessible. An attacker can craft a malicious URL containing the pathinfo parameter with embedded script code and trick a victim into clicking it (e.g., via email or a phishing link). No special network position or user interaction beyond clicking the link is needed. The reflected XSS executes in the context of the victim's session with the application.

Impact

Successful exploitation allows the attacker to execute arbitrary JavaScript in the victim's browser within the security context of the IBM Cognos 8 BI domain. This leads to potential session hijacking, defacement, or theft of sensitive data displayed by the application. The attacker gains the same access privileges as the targeted user.

Mitigation

IBM released Fix Pack 1 (FP1) for Cognos 8 BI 8.4.1, which addresses this vulnerability [1]. All users should upgrade to 8.4.1 FP1 or later. No workarounds are documented. This CVE is not listed on the Known Exploited Vulnerabilities (KEV) catalog.

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • cpe:2.3:a:ibm:cognos_8_business_intelligence:8.4.1:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:ibm:cognos_8_business_intelligence:8.4.1:*:*:*:*:*:*:*
    • (no CPE)range: <8.4.1 FP1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

7

News mentions

0

No linked articles in our index yet.