Cognos Controller Vulnerable to External Service Interaction Attack
CVE-2022-22364
5.3MEDIUM
What is CVE-2022-22364?
IBM Cognos Controller versions 10.4.1, 10.4.2, and 11.0.0 are impacted by a vulnerability that allows a remote attacker to exploit improper validation of user input. This vulnerability facilitates external service interaction attacks, where an attacker can manipulate the application to make server-side DNS lookups or HTTP requests to arbitrary domain names. By leveraging crafted input, attackers can redirect the application server to initiate unwanted interactions with other systems, potentially leading to further security breaches. Relevant security measures should be taken to mitigate the risks associated with this vulnerability.
Affected Version(s)
Cognos Controller 10.4.1, 10.4.2, 11.0.0