Cognos Controller Vulnerability Could Lead to Sensitive Information Disclosure
CVE-2023-23474
5.3MEDIUM
Summary
A vulnerability exists in IBM Cognos Controller versions 10.4.1, 10.4.2, and 11.0.0 that could allow a remote attacker to gain unauthorized access to sensitive information. This occurs when the application returns a stack trace in the browser, potentially exposing critical data and vulnerabilities that could be exploited. Users and administrators of IBM Cognos Controller should be aware of this issue and take appropriate measures to secure their deployments.
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Collectors
NVD Database