IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could be vulnerable to sensitive information exposure by passing API keys to log files. If these keys contain sensitive information, it could lead to further attacks. IBM X-Force ID: 240450.
References
Link | Resource |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/240450 | VDB Entry Vendor Advisory |
https://www.ibm.com/support/pages/node/6841801 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
23 Dec 2022, 19:48
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://www.ibm.com/support/pages/node/6841801 - Patch, Vendor Advisory | |
References | (MISC) https://exchange.xforce.ibmcloud.com/vulnerabilities/240450 - VDB Entry, Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
CPE | cpe:2.3:a:ibm:cognos_analytics:11.1.7:fixpack3:*:*:*:*:*:* cpe:2.3:a:ibm:cognos_analytics:11.1.7:-:*:*:*:*:*:* cpe:2.3:a:ibm:cognos_analytics:*:*:*:*:*:*:*:* cpe:2.3:a:ibm:cognos_analytics:11.1.7:fixpack5:*:*:*:*:*:* cpe:2.3:a:ibm:cognos_analytics:11.1.7:fixpack4:*:*:*:*:*:* cpe:2.3:a:ibm:cognos_analytics:11.1.7:fixpack1:*:*:*:*:*:* cpe:2.3:a:ibm:cognos_analytics:11.1.7:fixpack2:*:*:*:*:*:* |
|
CWE | CWE-532 |
19 Dec 2022, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-12-19 21:15
Updated : 2024-02-04 23:14
NVD link : CVE-2022-43887
Mitre link : CVE-2022-43887
CVE.ORG link : CVE-2022-43887
JSON object : View
Products Affected
ibm
- cognos_analytics
CWE
CWE-532
Insertion of Sensitive Information into Log File