PT-2020-18201 · Ibm · Ibm Cognos Controller
Faraz Khan
·
Published
2020-11-11
·
Updated
2021-07-21
·
CVE-2020-4685
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
IBM Cognos Controller versions 10.3.0 through 10.4.2
Description
A low-level user with Administration rights to the server where the application is installed can escalate their privilege from Low level to Super Admin and gain access to Create/Update/Delete any level of user in Cognos Controller.
Recommendations
For IBM Cognos Controller versions 10.3.0 through 10.4.2, restrict access to Administration rights on the server where the application is installed to prevent privilege escalation.
As a temporary workaround, consider disabling the ability to Create/Update/Delete users in Cognos Controller until a patch is available.
Restrict access to sensitive areas of the application to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibm Cognos Controller