CVE-2019-4412: Infoleak
IBM Cognos Controller stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-4412.
What is the severity of CVE-2019-4412?
The severity of CVE-2019-4412 is medium with a severity value of 5.3.
How does this vulnerability impact IBM Cognos Controller?
This vulnerability allows unauthorized parties to access sensitive information stored in URL parameters, leading to potential information disclosure.
Which versions of IBM Cognos Controller are affected by this vulnerability?
This vulnerability affects IBM Cognos Controller versions 10.3.0, 10.3.1, 10.4.0, and 10.4.1.
How can I mitigate this vulnerability?
To mitigate this vulnerability, ensure that unauthorized parties do not have access to the URLs containing sensitive information. Also, review server logs, disable referrer headers if not necessary, and clear browser history regularly.