CVE-2017-1784: Infoleak
Published Jan 29, 2018
·Updated
IBM Cognos Analytics 11.0 could produce results in temporary files that contain highly sensitive information that can be read by a local user. IBM X-Force ID: 136858.
Affected Software
9 affected components
IBM Cognos Analytics=11.0.0
IBM Cognos Analytics=11.0.1
IBM Cognos Analytics=11.0.2
IBM Cognos Analytics=11.0.3
IBM Cognos Analytics=11.0.4
IBM Cognos Analytics=11.0.5.0
IBM Cognos Analytics=11.0.6.0
IBM Cognos Analytics=11.0.7.0
NetApp OnCommand Insight
Remediation
Patch Available
Event History
Jan 29, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-1784?
CVE-2017-1784 is considered a high severity vulnerability due to its potential exposure of sensitive information.
2
How do I fix CVE-2017-1784?
To address CVE-2017-1784, upgrade IBM Cognos Analytics to version 11.0.7.0 or later.
3
What types of information are affected by CVE-2017-1784?
CVE-2017-1784 affects temporary files that may contain highly sensitive information accessible by local users.
4
Which versions of IBM Cognos Analytics are vulnerable to CVE-2017-1784?
IBM Cognos Analytics versions 11.0.0 through 11.0.6.0 are vulnerable to CVE-2017-1784.
5
Can CVE-2017-1784 be exploited remotely?
CVE-2017-1784 cannot be exploited remotely as it requires local user access to read the sensitive temporary files.