← Back

CVE-2023-35011

nvd nist
Published: Aug 16, 2023Modified: Nov 21, 2024

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.5
Source: NVD

Description

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 257705.

Affected (14)

1 product
Cognos Analytics
Configuration A
14 vulnerable
Vulnerable SoftwareAffected Versions
Ibm
From 11.1.0 to 11.1.7
From 11.2.0 to 11.2.4
Version 11.1.7
Version 11.1.7 interimfix1
Version 11.1.7 interimfix2
Version 11.1.7 interimfix3
Version 11.1.7 interimfix4
Version 11.1.7 interimfix5
Version 11.1.7 interimfix6
Version 11.1.7 interimfix7
Version 11.1.7 interimfix8
Version 11.1.7 interimfix9
Version 11.2.4
Version 11.2.4 fixpack1

References (8)

Source: psirt@us.ibm.com
VDB EntryVendor Advisory
Source: psirt@us.ibm.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
VDB EntryVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.