CVE-2020-4561

CRITICAL

IBM Cognos Analytics 11.0 and 11.1 DQM API allows submitting of all control requests in unauthenticated sessions. This allows a remote attacker who can access a valid CA endpoint to read and write ...

Affects 2 products across 2 vendors.

BCS7.51
CVSS 3.110.0
EPSS2.9%
Percentile86th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, can impact systems beyond the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-829: CWE-829
Related Attack Patterns (CAPEC)
CAPEC-201 Serialized Data External Linking
via CWE-829
CAPEC-228 DTD Injection
via CWE-829
CAPEC-252 PHP Local File Inclusion
via CWE-829
CAPEC-263 Force Use of Corrupted Files
via CWE-829
CAPEC-538 Open-Source Library Manipulation
via CWE-829
Show all 13

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

IBM Cognos Analytics 11.0 and 11.1 DQM API allows unauthenticated users to submit control requests, enabling remote attackers to read and write files to the system.

BSID: BS-2021-GLOBAL-201763-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2020-4561?
IBM Cognos Analytics 11.0 and 11.1 DQM API allows unauthenticated users to submit control requests, enabling remote attackers to read and write files to the system.
What is the CVSS score for CVE-2020-4561?
CVE-2020-4561 has CVSS 10.0 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. EPSS: 2.9%.
Is CVE-2020-4561 actively exploited?
No confirmed active exploitation of CVE-2020-4561 as of 2026-05-30.
How do I remediate CVE-2020-4561?
Priority: IMMEDIATE. Advisory: https://www.ibm.com/support/pages/node/6451705 PSIRT: [email protected]
What systems are affected by CVE-2020-4561?
CVE-2020-4561 affects: Ibm, Netapp.
Vulnerability Details
CVE IDCVE-2020-4561
BSIDBS-2021-GLOBAL-201763-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Published2021-06-01
Last Modified2024-11-21
ICS Relevance0%
Weakness (CWE)
SourceNVD
Official Description

IBM Cognos Analytics 11.0 and 11.1 DQM API allows submitting of all control requests in unauthenticated sessions. This allows a remote attacker who can access a valid CA endpoint to read and write files to the Cognos Analytics system. IBM X-Force ID: 183903.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

An attacker can exploit this vulnerability by sending specially crafted requests to the DQM API endpoint of IBM Cognos Analytics, without the need for authentication, to perform unauthorized file operations.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Ibm Cognos Analytics
Netapp Oncommand Insight
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 1880 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hashe1d224f0061aa70a5737eb66638d78eb8117bc9849e3d35f64a463d139049b06a2b75c133175c0b851a643a69c8cb033b0d1a32057b882b5deef9ae1159f42e8
Related CVEs affecting Ibm
CVE-2001-0554 10.0 Buffer overflow in BSD-based telnetd telnet daemon on various operating syste... CVE-2006-5008 10.0 Unspecified vulnerability in utape in IBM AIX 5.2.0 and 5.3.0 allows attacker... CVE-2000-0677 10.0 Buffer overflow in IBM Net.Data db2www CGI program allows remote attackers to... CVE-2002-0679 10.0 Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database ser... CVE-2002-0743 10.0 mail and mailx in AIX 4.3.3 core dump when called with a very long argument, ...
View all Ibm CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →