CVE-2021-20451: IBM Cognos Controller SQL injection
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 196643.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-20451?
CVE-2021-20451 is considered a high severity vulnerability due to its potential for SQL injection attacks.
How do I fix CVE-2021-20451?
To mitigate CVE-2021-20451, upgrade to a patched version of IBM Cognos Controller that addresses the SQL injection vulnerability.
Which versions of IBM Cognos Controller are affected by CVE-2021-20451?
CVE-2021-20451 affects IBM Cognos Controller versions 10.4.1, 10.4.2, and 11.0.0.
Can CVE-2021-20451 be exploited remotely?
Yes, CVE-2021-20451 can be exploited remotely by sending specially crafted SQL statements.
What types of data can be compromised due to CVE-2021-20451?
Exploitation of CVE-2021-20451 can allow attackers to view, add, modify, or delete information in the back-end database.