CVE-2021-29768: Medium severity IBM Cognos Analytics vulnerability
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a low level user to obtain sensitive information from the details of the 'Cloud Storage' page for which they should not have access. IBM X-Force ID: 202682.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-29768?
CVE-2021-29768 refers to a vulnerability in IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 that could allow a low level user to obtain sensitive information from the details of the 'Cloud Storage' page for which they should not have access.
Which versions of IBM Cognos Analytics are affected by CVE-2021-29768?
IBM Cognos Analytics versions 11.1.7, 11.2.0, and 11.2.1 are affected by CVE-2021-29768.
What is the severity of CVE-2021-29768?
CVE-2021-29768 has a severity rating of 6.5, which is considered medium.
How can a low level user exploit CVE-2021-29768?
A low level user can exploit CVE-2021-29768 by accessing and obtaining sensitive information from the 'Cloud Storage' page in IBM Cognos Analytics 11.1.7, 11.2.0, or 11.2.1.
Are there any available fixes for CVE-2021-29768?
IBM has not provided specific fixes for CVE-2021-29768, but users are advised to follow the recommendations and security measures outlined in the IBM advisory.