CVE-2019-4178: Path Traversal
Published Apr 15, 2019
·Updated
IBM Cognos Analytics 11 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request to write or view arbitrary files on the system. IBM X-Force ID: 158919.
Affected Software
1 affected component
IBM Cognos Analytics>=11.0.0.0<=11.0.13.0
Event History
Apr 15, 2019
CVE Published
via MITRE·02:55 PM
Data Sourced
via MITRE·02:55 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-4178?
CVE-2019-4178 has a moderate severity level due to its potential for unauthorized access to sensitive files.
2
How do I fix CVE-2019-4178?
To fix CVE-2019-4178, upgrade IBM Cognos Analytics to version 11.0.13 or later.
3
What type of attack does CVE-2019-4178 enable?
CVE-2019-4178 enables a remote attacker to conduct directory traversal attacks.
4
Which versions of IBM Cognos Analytics are affected by CVE-2019-4178?
CVE-2019-4178 affects IBM Cognos Analytics versions from 11.0.0.0 to 11.0.13.0.
5
Can CVE-2019-4178 allow data exposure?
Yes, CVE-2019-4178 can allow an attacker to view arbitrary files, potentially exposing sensitive data.