First published: Mon Dec 30 2019(Updated: )
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 168924.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Analytics | =11.0.0 | |
IBM Cognos Analytics | =11.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-4623.
The severity level of CVE-2019-4623 is medium with a score of 5.4.
The vulnerability allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure.
IBM Cognos Analytics 11.0 and 11.1 are affected by CVE-2019-4623.
Users should apply the necessary security patches or updates provided by IBM to fix the vulnerability.