First published: Mon Jan 29 2018(Updated: )
IBM Cognos Analytics 11.0 could produce results in temporary files that contain highly sensitive information that can be read by a local user. IBM X-Force ID: 136858.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Analytics | =11.0.0 | |
IBM Cognos Analytics | =11.0.1 | |
IBM Cognos Analytics | =11.0.2 | |
IBM Cognos Analytics | =11.0.3 | |
IBM Cognos Analytics | =11.0.4 | |
IBM Cognos Analytics | =11.0.5.0 | |
IBM Cognos Analytics | =11.0.6.0 | |
IBM Cognos Analytics | =11.0.7.0 | |
NetApp OnCommand Insight |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1784 is considered a high severity vulnerability due to its potential exposure of sensitive information.
To address CVE-2017-1784, upgrade IBM Cognos Analytics to version 11.0.7.0 or later.
CVE-2017-1784 affects temporary files that may contain highly sensitive information accessible by local users.
IBM Cognos Analytics versions 11.0.0 through 11.0.6.0 are vulnerable to CVE-2017-1784.
CVE-2017-1784 cannot be exploited remotely as it requires local user access to read the sensitive temporary files.