PT-2019-17044 · Ibm · Ibm Cognos Analytics

Published

2019-12-30

·

Updated

2023-01-20

·

CVE-2019-4343

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Cognos Analytics versions 11.0 through 11.1
Description The issue allows overly permissive cross-origin resource sharing, which could enable an attacker to transfer private information. An attacker could exploit this to access content that should be restricted.
Recommendations For IBM Cognos Analytics versions 11.0 through 11.1, consider restricting access to sensitive content until a fix is available. As a temporary workaround, restrict the use of cross-origin resource sharing features in IBM Cognos Analytics until a patch is available.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2019-4343

Affected Products

Ibm Cognos Analytics