6.5

CVE-2022-34339

"IBM Cognos Analytics 11.2.1, 11.2.0, 11.1.7 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 229963."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Cognos Analytics Version >= 11.1.0 < 11.1.7
Ibm ≫ Cognos Analytics Version 11.1.7 Update -
Ibm ≫ Cognos Analytics Version 11.1.7 Update fixpack1
Ibm ≫ Cognos Analytics Version 11.1.7 Update fixpack2
Ibm ≫ Cognos Analytics Version 11.1.7 Update fixpack3
Ibm ≫ Cognos Analytics Version 11.1.7 Update fixpack4
Ibm ≫ Cognos Analytics Version 11.2.0
Ibm ≫ Cognos Analytics Version 11.2.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.41% 0.339
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA-ADP 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-312 Cleartext Storage of Sensitive Information

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

https://www.ibm.com/support/pages/node/6828527
Patch
Vendor Advisory