CVE-2022-43883
19.12.2022, 21:15
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could be vulnerable to a Log Injection attack by constructing URLs from user-controlled data. This could enable attackers to make arbitrary requests to the internal network or to the local file system. IBM X-Force ID: 240266.Enginsight
Vendor | Product | Version |
---|---|---|
ibm | cognos_analytics | 11.1.0 ≤ 𝑥 ≤ 11.1.7 |
ibm | cognos_analytics | 11.2.0 ≤ 𝑥 ≤ 11.2.3 |
ibm | cognos_analytics | 11.1.7:fixpack1 |
ibm | cognos_analytics | 11.1.7:fixpack2 |
ibm | cognos_analytics | 11.1.7:fixpack3 |
ibm | cognos_analytics | 11.1.7:fixpack4 |
ibm | cognos_analytics | 11.1.7:fixpack5 |
𝑥
= Vulnerable software versions