CVE-2023-35011
16.08.2023, 23:15
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 257705.
Vendor | Product | Version |
---|---|---|
ibm | cognos_analytics | 11.1.0 ≤ 𝑥 < 11.1.7 |
ibm | cognos_analytics | 11.2.0 ≤ 𝑥 < 11.2.4 |
ibm | cognos_analytics | 11.1.7 |
ibm | cognos_analytics | 11.1.7:interimfix1 |
ibm | cognos_analytics | 11.1.7:interimfix2 |
ibm | cognos_analytics | 11.1.7:interimfix3 |
ibm | cognos_analytics | 11.1.7:interimfix4 |
ibm | cognos_analytics | 11.1.7:interimfix5 |
ibm | cognos_analytics | 11.1.7:interimfix6 |
ibm | cognos_analytics | 11.1.7:interimfix7 |
ibm | cognos_analytics | 11.1.7:interimfix8 |
ibm | cognos_analytics | 11.1.7:interimfix9 |
ibm | cognos_analytics | 11.2.4 |
ibm | cognos_analytics | 11.2.4:fixpack1 |
𝑥
= Vulnerable software versions
References