PT-2020-10977 · Ibm · Ibm Cognos Analytics
Published
2020-08-03
·
Updated
2020-08-03
·
CVE-2019-4589
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Cognos Analytics versions 11.0 through 11.1
Description
The issue concerns a privilege escalation problem where the "My schedules and subscriptions" page is accessible to less privileged users.
Recommendations
For IBM Cognos Analytics versions 11.0 through 11.1, restrict access to the "My schedules and subscriptions" page to prevent less privileged users from accessing it.
As a temporary workaround, consider limiting the visibility of the "My schedules and subscriptions" page until a patch is available.
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Cognos Analytics