PT-2022-27041 · Ibm · Ibm Cognos Analytics
Published
2022-12-19
·
Updated
2022-12-23
·
CVE-2022-43887
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Cognos Analytics versions 11.1.7 through 11.2.1
Description
The issue concerns sensitive information exposure by passing API keys to log files. If these keys contain sensitive information, it could lead to further attacks.
Recommendations
For IBM Cognos Analytics versions 11.1.7 through 11.2.1, consider restricting access to log files to minimize the risk of sensitive information exposure. As a temporary workaround, review log file configurations to prevent API keys from being written to logs until a more permanent solution is available.
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Cognos Analytics