CVE-2019-4173: Infoleak
IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 could allow a remote attacker to obtain sensitive information, caused by a flaw in the HTTP OPTIONS method, aka Optionsbleed. By sending an OPTIONS HTTP request, a remote attacker could exploit this vulnerability to read secret data from process memory and obtain sensitive information. IBM X-Force ID: 158878.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-4173?
CVE-2019-4173 is a vulnerability in IBM Cognos Controller versions 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 that could allow a remote attacker to obtain sensitive information.
How does CVE-2019-4173 work?
CVE-2019-4173 is caused by a flaw in the HTTP OPTIONS method, also known as Optionsbleed, which can be exploited by sending an OPTIONS HTTP request to read secret data.
What is the severity of CVE-2019-4173?
CVE-2019-4173 has a severity level of 6.5, which is considered medium.
Which versions of IBM Cognos Controller are affected by CVE-2019-4173?
CVE-2019-4173 affects IBM Cognos Controller versions 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0.
How can I fix CVE-2019-4173?
To fix CVE-2019-4173, IBM Cognos Controller users should apply the necessary patches or updates provided by IBM.