CVE-2019-4231: CSRF
Published Dec 20, 2019
·Updated
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 159356.
Affected Software
6 affected components
IBM Cognos Analytics>=11.0.0<=11.0.12
IBM Cognos Analytics>=11.1.0<11.1.4.0
IBM Cognos Analytics=11.0.13
IBM Cognos Analytics=11.0.13-fixpack1
IBM Cognos Analytics=11.0.13-fixpack2
NetApp OnCommand Insight
Remediation
Patch Available
Event History
Dec 20, 2019
CVE Published
via MITRE·04:25 PM
Data Sourced
via MITRE·04:25 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-4231?
CVE-2019-4231 has a medium severity rating due to its potential for cross-site request forgery attacks.
2
How do I fix CVE-2019-4231?
To fix CVE-2019-4231, update IBM Cognos Analytics to the latest version or apply recommended patches.
3
What is the exploit type of CVE-2019-4231?
CVE-2019-4231 is an exploit type categorized as cross-site request forgery (CSRF).
4
Which versions of IBM Cognos Analytics are affected by CVE-2019-4231?
CVE-2019-4231 affects IBM Cognos Analytics versions 11.0.0 to 11.0.12 and 11.1.0 to 11.1.4.0.
5
What kind of attack can CVE-2019-4231 allow?
CVE-2019-4231 can allow an attacker to perform unauthorized actions by leveraging the trust relationship of the website.