CVE-2020-4354: XSS
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 178506.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-4354?
The severity of CVE-2020-4354 is medium with a severity value of 5.4.
How does CVE-2020-4354 affect IBM Cognos Analytics?
CVE-2020-4354 affects IBM Cognos Analytics versions 11.0.0 and 11.1.0.
What is cross-site scripting?
Cross-site scripting (XSS) is a vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.
What can an attacker do with cross-site scripting in IBM Cognos Analytics?
An attacker can embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within a trusted session.
How can I fix CVE-2020-4354 in IBM Cognos Analytics?
Apply the relevant security patches or updates provided by IBM to fix CVE-2020-4354 in IBM Cognos Analytics.