CVE-2019-4471: Medium severity ibm cognos analytics vulnerability
Published May 31, 2021
·Updated
IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain sensitive information, caused by the failure to set the secure flag for a sensitive cookie in an HTTPS session. A remote attacker could exploit this vulnerability to obtain sensitive information. IBM X-Force ID: 163780.
Affected Software
3 affected components
IBM Cognos Analytics=11.0.0
IBM Cognos Analytics=11.1.0
NetApp OnCommand Insight
Remediation
Patch Available
Event History
May 31, 2021
CVE Published
via MITRE·03:10 PM
Data Sourced
via MITRE·03:10 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-4471?
The severity of CVE-2019-4471 is medium with a severity value of 6.5.
2
How can a remote attacker exploit CVE-2019-4471?
A remote attacker can exploit CVE-2019-4471 to obtain sensitive information.
3
Which versions of IBM Cognos Analytics are affected by CVE-2019-4471?
IBM Cognos Analytics 11.0 and 11.1 are affected by CVE-2019-4471.
4
What is the CWE ID of CVE-2019-4471?
The CWE ID of CVE-2019-4471 is 311.
5
Where can I find more information about CVE-2019-4471?
You can find more information about CVE-2019-4471 at the following references: [link1], [link2], [link3].