Cognos Controller Vulnerable to External Service Interaction Attack
CVE-2022-22364
5.3MEDIUM
Summary
IBM Cognos Controller versions 10.4.1, 10.4.2, and 11.0.0 are impacted by a vulnerability that allows a remote attacker to exploit improper validation of user input. This vulnerability facilitates external service interaction attacks, where an attacker can manipulate the application to make server-side DNS lookups or HTTP requests to arbitrary domain names. By leveraging crafted input, attackers can redirect the application server to initiate unwanted interactions with other systems, potentially leading to further security breaches. Relevant security measures should be taken to mitigate the risks associated with this vulnerability.
Affected Version(s)
Cognos Controller 10.4.1, 10.4.2, 11.0.0
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved