Information Disclosure Vulnerability in IBM Cognos Controller
CVE-2021-20455

3.7LOW

Key Information:

Vendor
IBM
Vendor
CVE Published:
7 January 2025

Summary

A potential information disclosure vulnerability exists in IBM Cognos Controller versions 11.0.0 to 11.0.1 and IBM Controller 11.1.0. This vulnerability may allow a remote attacker to glean sensitive information through the improper handling of detailed error messages returned by the system. These error messages could reveal insights that may facilitate further attacks, making it imperative for users to mitigate this risk.

Affected Version(s)

Cognos Controller 11.0.0 <= 11.0.1

Controller 11.1.0

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.