PT-2022-2571 · Ibm · Ibm Cognos Controller

Published

2022-01-20

·

Updated

2022-01-27

·

CVE-2020-4877

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions IBM Cognos Controller versions 10.4.0 through 10.4.2
Description The issue is related to weaknesses in the authorization mechanism of IBM Cognos Controller, which could allow a remote attacker to impact the confidentiality, integrity, and availability of protected information by using public fields in public classes.
Recommendations For versions 10.4.0 through 10.4.2, consider restricting access to public fields in public classes as a temporary workaround until a patch is available.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-03013
CVE-2020-4877

Affected Products

Ibm Cognos Controller