First published: Fri Dec 20 2019(Updated: )
IBM Cognos Business Intelligence 10.2.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 153179.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Business Intelligence | =10.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1934 is classified as a moderate severity vulnerability due to the potential for unauthorized actions on behalf of a trusted user.
To mitigate CVE-2018-1934, ensure you apply the latest security patches provided by IBM for Cognos Business Intelligence 10.2.2.
CVE-2018-1934 affects users of IBM Cognos Business Intelligence version 10.2.2.
CVE-2018-1934 allows attackers to perform cross-site request forgery attacks, potentially executing unauthorized actions.
Yes, CVE-2018-1934 is a web application security vulnerability specifically related to cross-site request forgery.