CVE-2019-4174: Medium severity ibm cognos controller vulnerability
Published Jun 17, 2019
·Updated
IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 158879.
Affected Software
5 affected components
IBM Cognos Controller=10.2.0
IBM Cognos Controller=10.2.1
IBM Cognos Controller=10.3.0
IBM Cognos Controller=10.3.1
IBM Cognos Controller=10.4.0
Remediation
Patch Available
Event History
Jun 17, 2019
CVE Published
via MITRE·03:10 PM
Data Sourced
via MITRE·03:10 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-4174?
CVE-2019-4174 has a severity of medium.
2
What is the affected software for CVE-2019-4174?
IBM Cognos Controller versions 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 are affected.
3
How can this vulnerability be exploited?
This vulnerability allows web pages to be stored locally and read by another user on the system.
4
How can I fix CVE-2019-4174?
To fix CVE-2019-4174, it is recommended to update IBM Cognos Controller to a version that has a security patch.
5
Where can I find more information about CVE-2019-4174?
More information about CVE-2019-4174 can be found at the following references: [Reference 1](http://www.ibm.com/support/docview.wss?uid=ibm10886913), [Reference 2](https://exchange.xforce.ibmcloud.com/vulnerabilities/158879).