CVE-2017-1428: Input Validation
IBM Cognos Analytics 11.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 127583.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1428?
CVE-2017-1428 is classified as a moderate severity vulnerability that allows remote click hijacking.
How do I fix CVE-2017-1428?
To fix CVE-2017-1428, upgrade to a patched version of IBM Cognos Analytics that addresses this vulnerability.
Which versions of IBM Cognos Analytics are affected by CVE-2017-1428?
IBM Cognos Analytics versions 11.0.0 to 11.0.6 are affected by CVE-2017-1428.
Can CVE-2017-1428 lead to further attacks?
Yes, CVE-2017-1428 can potentially lead to further attacks if a victim's click actions are hijacked.
Are there any known exploits for CVE-2017-1428?
While there are no widespread known exploits for CVE-2017-1428, it remains a vulnerability that can be exploited by attackers.