PT-2021-3243 · Ibm · Ibm Cognos Analytics

Published

2021-05-31

·

Updated

2021-12-02

·

CVE-2020-4561

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM Cognos Analytics versions 11.0 through 11.1
Description The issue is related to the inclusion of features from an untrusted controlled area in the IBM Cognos Analytics online service. This could allow a remote attacker to impact the confidentiality, integrity, and availability of protected information. A remote attacker who can access a valid endpoint can read and write files to the Cognos Analytics system, as the DQM API allows the submission of all control requests in unauthenticated sessions.
Recommendations For IBM Cognos Analytics versions 11.0 through 11.1, consider restricting access to the DQM API to prevent unauthenticated sessions from submitting control requests. As a temporary workaround, limit the ability to read and write files to the Cognos Analytics system until a fix is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-02961
CVE-2020-4561

Affected Products

Ibm Cognos Analytics