CVE-2020-4300: XEE
Published May 31, 2021
·Updated
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 176607.
Affected Software
3 affected components
IBM Cognos Analytics=11.0.0
IBM Cognos Analytics=11.1.0
NetApp OnCommand Insight
Remediation
Patch Available
Event History
May 31, 2021
CVE Published
via MITRE·03:10 PM
Data Sourced
via MITRE·03:10 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this security issue?
The vulnerability ID for this security issue is CVE-2020-4300.
2
What is the title of this vulnerability?
The title of this vulnerability is 'IBM Cognos Analytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack'.
3
What is the severity rating of CVE-2020-4300?
The severity rating of CVE-2020-4300 is high.
4
What is the affected software for this vulnerability?
The affected software for this vulnerability is IBM Cognos Analytics 11.0 and 11.1.
5
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by conducting an XML External Entity Injection (XXE) attack when processing XML data.