First published: Mon May 31 2021(Updated: )
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 178506.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Analytics | =11.0.0 | |
IBM Cognos Analytics | =11.1.0 | |
NetApp OnCommand Insight |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-4354 is medium with a severity value of 5.4.
CVE-2020-4354 affects IBM Cognos Analytics versions 11.0.0 and 11.1.0.
Cross-site scripting (XSS) is a vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.
An attacker can embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within a trusted session.
Apply the relevant security patches or updates provided by IBM to fix CVE-2020-4354 in IBM Cognos Analytics.