First published: Fri Dec 03 2021(Updated: )
IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 209706.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Analytics | >=11.1.0<11.1.7 | |
IBM Cognos Analytics | =11.1.7 | |
IBM Cognos Analytics | =11.1.7-fixpack1 | |
IBM Cognos Analytics | =11.1.7-fixpack2 | |
IBM Cognos Analytics | =11.1.7-fixpack3 | |
IBM Cognos Analytics | =11.2.0 | |
NetApp OnCommand Insight |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-38909 is a vulnerability in IBM Cognos Analytics that allows users to embed arbitrary JavaScript code in the Web UI potentially leading to credentials disclosure within a trusted session.
CVE-2021-38909 has a severity rating of 5.4, which is considered medium.
CVE-2021-38909 allows users to exploit a cross-site scripting vulnerability in IBM Cognos Analytics, which can lead to credentials disclosure within a trusted session.
The risk of CVE-2021-38909 is that an attacker can inject arbitrary JavaScript code into the Web UI of IBM Cognos Analytics, potentially leading to credentials disclosure.
Please refer to the official IBM Cognos Analytics documentation or contact IBM support for information on available fixes for CVE-2021-38909.