CVE-2021-38945: Malicious File Upload
Published Jun 24, 2022
·Updated
IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 could allow a remote attacker to upload arbitrary files, caused by improper content validation. IBM X-Force ID: 211238.
Affected Software
9 affected components
IBM Cognos Analytics>=11.1.0<11.1.7
IBM Cognos Analytics=11.1.7
IBM Cognos Analytics=11.1.7-fixpack1
IBM Cognos Analytics=11.1.7-fixpack2
IBM Cognos Analytics=11.1.7-fixpack3
IBM Cognos Analytics=11.1.7-fixpack4
IBM Cognos Analytics=11.2.0
IBM Cognos Analytics=11.2.1
NetApp OnCommand Insight
Remediation
Patch Available
Event History
Jun 24, 2022
CVE Published
via MITRE·03:35 PM
Data Sourced
via MITRE·03:35 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-38945?
CVE-2021-38945 refers to a vulnerability in IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 that allows a remote attacker to upload arbitrary files.
2
How can this vulnerability be exploited?
This vulnerability can be exploited by a remote attacker to upload arbitrary files due to improper content validation.
3
What is the severity of CVE-2021-38945?
CVE-2021-38945 has a severity rating of 9.8 (Critical).
4
Which versions of IBM Cognos Analytics are affected?
IBM Cognos Analytics versions 11.2.1, 11.2.0, and 11.1.7 are affected by this vulnerability.
5
How can I fix CVE-2021-38945?
To fix CVE-2021-38945, it is recommended to apply the necessary security patches or updates provided by IBM.