5.3

CVE-2023-35009

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a remote attacker to obtain system information without authentication which could be used in reconnaissance to gather information that could be used for future attacks.  IBM X-Force ID:  257703.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IbmCognos Analytics Version >= 11.1.0 < 11.1.7
IbmCognos Analytics Version >= 11.2.0 < 11.2.4
IbmCognos Analytics Version11.1.7 Update-
IbmCognos Analytics Version11.1.7 Updateinterimfix1
IbmCognos Analytics Version11.1.7 Updateinterimfix2
IbmCognos Analytics Version11.1.7 Updateinterimfix3
IbmCognos Analytics Version11.1.7 Updateinterimfix4
IbmCognos Analytics Version11.1.7 Updateinterimfix5
IbmCognos Analytics Version11.1.7 Updateinterimfix6
IbmCognos Analytics Version11.1.7 Updateinterimfix7
IbmCognos Analytics Version11.1.7 Updateinterimfix8
IbmCognos Analytics Version11.1.7 Updateinterimfix9
IbmCognos Analytics Version11.2.4 Update-
IbmCognos Analytics Version11.2.4 Updatefixpack1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.06% 0.184
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
psirt@us.ibm.com 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE-209 Generation of Error Message Containing Sensitive Information

The product generates an error message that includes sensitive information about its environment, users, or associated data.