PT-2025-7279 · Ibm · Ibm Controller+1
Published
2025-02-18
·
Updated
2025-02-22
·
CVE-2023-47160
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
IBM Cognos Controller versions 11.0.0 through 11.0.1 FP3
IBM Controller version 11.1.0
Description
The issue concerns an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this to expose sensitive information or consume memory resources.
Recommendations
For IBM Cognos Controller versions 11.0.0 through 11.0.1 FP3, consider disabling XML data processing until a patch is available.
For IBM Controller version 11.1.0, restrict access to XML data processing to minimize the risk of exploitation.
As a temporary workaround, consider disabling the XML External Entity Injection (XXE) attack vector until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Cognos Controller
Ibm Controller