First published: Fri May 12 2023(Updated: )
IBM Cognos Analytics 11.1 and 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 213966.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Analytics | =11.1 | |
IBM Cognos Analytics | =11.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-39036 is a cross-site scripting vulnerability in IBM Cognos Analytics 11.1 and 11.2.
CVE-2021-39036 allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within a trusted session.
The severity of CVE-2021-39036 vulnerability is medium with a CVSS score of 6.1.
To fix CVE-2021-39036 vulnerability, apply the recommended security patches or updates provided by IBM.
You can find more information about CVE-2021-39036 vulnerability at IBM X-Force ID 213966 and the provided reference links.