First published: Mon Mar 19 2018(Updated: )
IBM Predictive Solutions Foundation (IBM Cognos Analytics 11.0) reveals sensitive information in detailed error messages that could aid an attacker in further attacks against the system. IBM X-Force ID: 119619.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Analytics | =11.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2016-9711 is categorized as medium due to the potential for sensitive information disclosure.
To fix CVE-2016-9711, upgrade to a patched version of IBM Cognos Analytics that addresses the vulnerability.
CVE-2016-9711 exposes sensitive information through detailed error messages that could be leveraged by attackers.
CVE-2016-9711 specifically affects IBM Cognos Analytics version 11.0.0.
Yes, CVE-2016-9711 can be exploited remotely by an attacker who can trigger the error messages.