PT-2018-14450 · Ibm · Ibm Cognos Analytics

Publicado

2018-11-09

·

Atualizado

2019-10-09

·

CVE-2018-1842

CVSS v3.1

3.6

Baixa

VetorAV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions IBM Cognos Analytics 11 (affected versions not specified)
Description The issue concerns the IBM Cognos Analytics 11 Configuration tool, which under certain circumstances, bypasses OIDC namespace signature verification on its id token.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Verification of Cryptographic Signature

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-1842

Produtos afetados

Ibm Cognos Analytics