First published: Fri Jun 24 2022(Updated: )
IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 could allow a remote attacker to upload arbitrary files, caused by improper content validation. IBM X-Force ID: 211238.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Analytics | >=11.1.0<11.1.7 | |
IBM Cognos Analytics | =11.1.7 | |
IBM Cognos Analytics | =11.1.7-fixpack1 | |
IBM Cognos Analytics | =11.1.7-fixpack2 | |
IBM Cognos Analytics | =11.1.7-fixpack3 | |
IBM Cognos Analytics | =11.1.7-fixpack4 | |
IBM Cognos Analytics | =11.2.0 | |
IBM Cognos Analytics | =11.2.1 | |
NetApp OnCommand Insight |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-38945 refers to a vulnerability in IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 that allows a remote attacker to upload arbitrary files.
This vulnerability can be exploited by a remote attacker to upload arbitrary files due to improper content validation.
CVE-2021-38945 has a severity rating of 9.8 (Critical).
IBM Cognos Analytics versions 11.2.1, 11.2.0, and 11.1.7 are affected by this vulnerability.
To fix CVE-2021-38945, it is recommended to apply the necessary security patches or updates provided by IBM.