PT-2025-7279 · Ibm · Ibm Controller+1

Published

2025-02-18

·

Updated

2025-02-22

·

CVE-2023-47160

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:P
Name of the Vulnerable Software and Affected Versions IBM Cognos Controller versions 11.0.0 through 11.0.1 FP3 IBM Controller version 11.1.0
Description The issue concerns an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this to expose sensitive information or consume memory resources.
Recommendations For IBM Cognos Controller versions 11.0.0 through 11.0.1 FP3, consider disabling XML data processing until a patch is available. For IBM Controller version 11.1.0, restrict access to XML data processing to minimize the risk of exploitation. As a temporary workaround, consider disabling the XML External Entity Injection (XXE) attack vector until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XXE

Weakness Enumeration

Related Identifiers

BDU:2025-02079
CVE-2023-47160

Affected Products

Ibm Cognos Controller
Ibm Controller