Client-Side Desync Vulnerability in IBM Cognos Controller
CVE-2022-39163
4.7MEDIUM
What is CVE-2022-39163?
IBM Cognos Controller versions 11.0.0 through 11.1.0 are susceptible to a Client-Side Desync (CSD) attack. This vulnerability allows an attacker to exploit a desynchronized connection in the browser, potentially leading to the execution of cross-site scripting (XSS) attacks. Malicious actors can manipulate the user session or inject harmful scripts, compromising sensitive user data and application integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cognos Controller 11.0.0 <= 11.0.1
Controller 11.1.0