CVE-2020-4685: High severity ibm cognos controller vulnerability
A low level user of Cognos Controller who has Administration rights to the server where the application is installed, can escalate their privilege from Low level to Super Admin and gain access to Create/Update/Delete any level of user in Cognos Controller.
Other sources
A low level user of IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, 10.4.1, and 10.4.2 who has Administration rights to the server where the application is installed, can escalate their privilege from Low level to Super Admin and gain access to Create/Update/Delete any level of user in Cognos Controller. IBM X-Force ID: 186625.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this security issue?
The vulnerability ID of this security issue is CVE-2020-4685.
What is the severity level of CVE-2020-4685?
CVE-2020-4685 has a severity level of high.
Which software versions are affected by CVE-2020-4685?
IBM Cognos Controller versions 10.3.0, 10.3.1, 10.4.0, 10.4.1, and 10.4.2 are affected by CVE-2020-4685.
What can an attacker do if they exploit CVE-2020-4685?
If CVE-2020-4685 is exploited, a low level user with Administration rights to the server can escalate their privilege and gain Super Admin access, allowing them to create, update, and delete any level of user in Cognos Controller.
Where can I find more information about CVE-2020-4685?
You can find more information about CVE-2020-4685 on the IBM X-Force Exchange website and the IBM Support website.