PT-2019-17044 · Ibm · Ibm Cognos Analytics
CVE-2019-4343
·
Publicado
2019-12-30
·
Atualizado
2023-01-20
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Cognos Analytics versions 11.0 through 11.1
Description
The issue allows overly permissive cross-origin resource sharing, which could enable an attacker to transfer private information. An attacker could exploit this to access content that should be restricted.
Recommendations
For IBM Cognos Analytics versions 11.0 through 11.1, consider restricting access to sensitive content until a fix is available.
As a temporary workaround, restrict the use of cross-origin resource sharing features in IBM Cognos Analytics until a patch is available.
Correção
Incorrect Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ibm Cognos Analytics