First published: Wed Jun 22 2022(Updated: )
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a low level user to obtain sensitive information from the details of the 'Cloud Storage' page for which they should not have access. IBM X-Force ID: 202682.
Credit: psirt@us.ibm.com psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Analytics | >=11.1.0<11.1.7 | |
IBM Cognos Analytics | =11.1.7 | |
IBM Cognos Analytics | =11.1.7-fixpack1 | |
IBM Cognos Analytics | =11.1.7-fixpack2 | |
IBM Cognos Analytics | =11.1.7-fixpack3 | |
IBM Cognos Analytics | =11.1.7-fixpack4 | |
IBM Cognos Analytics | =11.2.0 | |
IBM Cognos Analytics | =11.2.1 | |
NetApp OnCommand Insight |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-29768 refers to a vulnerability in IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 that could allow a low level user to obtain sensitive information from the details of the 'Cloud Storage' page for which they should not have access.
IBM Cognos Analytics versions 11.1.7, 11.2.0, and 11.2.1 are affected by CVE-2021-29768.
CVE-2021-29768 has a severity rating of 6.5, which is considered medium.
A low level user can exploit CVE-2021-29768 by accessing and obtaining sensitive information from the 'Cloud Storage' page in IBM Cognos Analytics 11.1.7, 11.2.0, or 11.2.1.
IBM has not provided specific fixes for CVE-2021-29768, but users are advised to follow the recommendations and security measures outlined in the IBM advisory.