First published: Fri Apr 24 2020(Updated: )
IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 172519.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Analytics | >=11.0.0.0<11.0.13 | |
IBM Cognos Analytics | >=11.1.0<11.1.6 | |
NetApp OnCommand Insight |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-4729 is a vulnerability in IBM Cognos Analytics 11.0 and 11.1 that could allow a remote attacker to obtain sensitive information.
CVE-2019-4729 works by exploiting the behavior of IBM Cognos Analytics to return a detailed technical error message in the browser, which could contain sensitive information.
CVE-2019-4729 has a severity rating of 4.3, which is considered medium.
CVE-2019-4729 affects IBM Cognos Analytics versions 11.0.0.0 to 11.0.13 and versions 11.1.0 to 11.1.6.
To fix CVE-2019-4729, it is recommended to apply the necessary patches and updates provided by IBM.