Cross-Site Request Forgery in IBM Cognos Business Intelligence
CVE-2018-1934

4.3MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
20 December 2019

Summary

IBM Cognos Business Intelligence version 10.2.2 is susceptible to cross-site request forgery (CSRF), a vulnerability that enables attackers to execute unauthorized actions by exploiting a trusted user's session. This can lead to potential security breaches, allowing malicious actors to compromise user accounts and perform actions without the consent of the legitimate user. Organizations using this version should implement security measures to mitigate the risk associated with this vulnerability.

Affected Version(s)

Cognos Business Intelligence 10.2.2

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.