First published: Mon Nov 05 2018(Updated: )
IBM Cognos Analytics 11 Configuration tool, under certain circumstances, will bypass OIDC namespace signature verification on its id_token. IBM X-Force ID: 150902.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Analytics | >=11.0.0.0<=11.0.12.0 | |
NetApp OnCommand Insight |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1842 has a medium severity rating due to its potential impact on the security of authentication processes.
To fix CVE-2018-1842, update IBM Cognos Analytics to version 11.0.12 or higher to ensure proper validation of the OIDC namespace signature.
Exploiting CVE-2018-1842 could allow attackers to bypass the signature verification on id_token, leading to unauthorized access.
CVE-2018-1842 affects IBM Cognos Analytics versions between 11.0.0.0 and 11.0.12.0.
Yes, CVE-2018-1842 is also related to NetApp OnCommand Insight as it shares the same underlying vulnerability issues.