PT-2020-18201 · Ibm · Ibm Cognos Controller

Faraz Khan

·

Published

2020-11-11

·

Updated

2021-07-21

·

CVE-2020-4685

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM Cognos Controller versions 10.3.0 through 10.4.2
Description A low-level user with Administration rights to the server where the application is installed can escalate their privilege from Low level to Super Admin and gain access to Create/Update/Delete any level of user in Cognos Controller.
Recommendations For IBM Cognos Controller versions 10.3.0 through 10.4.2, restrict access to Administration rights on the server where the application is installed to prevent privilege escalation. As a temporary workaround, consider disabling the ability to Create/Update/Delete users in Cognos Controller until a patch is available. Restrict access to sensitive areas of the application to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-4685

Affected Products

Ibm Cognos Controller