CVE-2018-1842: Low severity IBM Cognos Analytics vulnerability
Published Nov 9, 2018
·Updated
IBM Cognos Analytics 11 Configuration tool, under certain circumstances, will bypass OIDC namespace signature verification on its idtoken. IBM X-Force ID: 150902.
Affected Software
2 affected components
IBM Cognos Analytics>=11.0.0.0<=11.0.12.0
NetApp OnCommand Insight
Remediation
Patch Available
Event History
Nov 9, 2018
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-1842?
CVE-2018-1842 has a medium severity rating due to its potential impact on the security of authentication processes.
2
How do I fix CVE-2018-1842?
To fix CVE-2018-1842, update IBM Cognos Analytics to version 11.0.12 or higher to ensure proper validation of the OIDC namespace signature.
3
What are the consequences of exploiting CVE-2018-1842?
Exploiting CVE-2018-1842 could allow attackers to bypass the signature verification on id_token, leading to unauthorized access.
4
Which versions of IBM Cognos Analytics are affected by CVE-2018-1842?
CVE-2018-1842 affects IBM Cognos Analytics versions between 11.0.0.0 and 11.0.12.0.
5
Is CVE-2018-1842 relevant to NetApp OnCommand Insight?
Yes, CVE-2018-1842 is also related to NetApp OnCommand Insight as it shares the same underlying vulnerability issues.