First published: Mon Dec 30 2019(Updated: )
IBM Cognos Analytics 11.0 and 11.1 allows overly permissive cross-origin resource sharing which could allow an attacker to transfer private information. An attacker could exploit this vulnerability to access content that should be restricted. IBM X-Force ID: 161422.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Analytics | =11.0.0 | |
IBM Cognos Analytics | =11.1.0 | |
NetApp OnCommand Insight |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-4343 is classified as a moderate severity vulnerability due to the potential for sensitive information exposure.
To fix CVE-2019-4343, configure proper cross-origin resource sharing (CORS) settings to restrict access.
If your system is affected by CVE-2019-4343, you should review and modify your CORS policies to enhance security.
Yes, CVE-2019-4343 can be exploited remotely by an attacker gaining unauthorized access to restricted content.
CVE-2019-4343 affects IBM Cognos Analytics versions 11.0.0 and 11.1.0.