CVE-2017-1779: High severity ibm cognos analytics vulnerability
Published Jan 29, 2018
·Updated
IBM Cognos Analytics 11.0 could store cached credentials locally that could be obtained by a local user. IBM X-Force ID: 136824.
Affected Software
9 affected components
IBM Cognos Analytics=11.0.0
IBM Cognos Analytics=11.0.1
IBM Cognos Analytics=11.0.2
IBM Cognos Analytics=11.0.3
IBM Cognos Analytics=11.0.4
IBM Cognos Analytics=11.0.5.0
IBM Cognos Analytics=11.0.6.0
IBM Cognos Analytics=11.0.7.0
NetApp OnCommand Insight
Remediation
Patch Available
Event History
Jan 29, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-1779?
CVE-2017-1779 has been assigned a medium severity level due to the risk of cached credentials being accessed by local users.
2
How do I fix CVE-2017-1779?
To address CVE-2017-1779, upgrade to IBM Cognos Analytics version 11.0.8 or later, where this vulnerability is resolved.
3
Which versions of IBM Cognos Analytics are affected by CVE-2017-1779?
Versions 11.0.0 through 11.0.7.0 of IBM Cognos Analytics are affected by CVE-2017-1779.
4
What type of vulnerability is CVE-2017-1779?
CVE-2017-1779 is a local security vulnerability related to the improper caching of user credentials.
5
Who can exploit CVE-2017-1779?
CVE-2017-1779 can be exploited by any local user who has access to the system running the affected versions of IBM Cognos Analytics.