Cognos Controller Vulnerable to External Service Interaction Attack
CVE-2022-22364

5.3MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
3 May 2024

Summary

IBM Cognos Controller versions 10.4.1, 10.4.2, and 11.0.0 are impacted by a vulnerability that allows a remote attacker to exploit improper validation of user input. This vulnerability facilitates external service interaction attacks, where an attacker can manipulate the application to make server-side DNS lookups or HTTP requests to arbitrary domain names. By leveraging crafted input, attackers can redirect the application server to initiate unwanted interactions with other systems, potentially leading to further security breaches. Relevant security measures should be taken to mitigate the risks associated with this vulnerability.

Affected Version(s)

Cognos Controller 10.4.1, 10.4.2, 11.0.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.