Cognos Controller Vulnerability Could Lead to Sensitive Information Disclosure
CVE-2023-23474

5.3MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
3 May 2024

Summary

A vulnerability exists in IBM Cognos Controller versions 10.4.1, 10.4.2, and 11.0.0 that could allow a remote attacker to gain unauthorized access to sensitive information. This occurs when the application returns a stack trace in the browser, potentially exposing critical data and vulnerabilities that could be exploited. Users and administrators of IBM Cognos Controller should be aware of this issue and take appropriate measures to secure their deployments.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

Collectors

NVD Database
.