CVE-2022-34357: IBM Cognos Analytics Mobile Server denial of service
IBM Cognos Analytics Mobile Server 11.1.7, 11.2.4, and 12.0.0 is vulnerable to Denial of Service due to due to weak or absence of rate limiting. By making unlimited http requests, it is possible for a single user to exhaust server resources over a period of time making service unavailable for other legitimate users. IBM X-Force ID: 230510.
Other sources
IBM Cognos Analytics Mobile Server is vulnerable to Denial of Service due to due to weak or absence of rate limiting. By making unlimited http requests, it is possible for a single user to exhaust server resources over a period of time making serviceunavailable for other legitimate users.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-34357?
CVE-2022-34357 has a severity rating that indicates it can lead to Denial of Service due to weak or absent rate limiting.
How do I fix CVE-2022-34357?
To fix CVE-2022-34357, apply the appropriate patches provided by IBM for affected versions of Cognos Analytics.
Which versions are affected by CVE-2022-34357?
Versions 11.1.7, 11.2.4, and 12.0.0 of IBM Cognos Analytics are affected by CVE-2022-34357.
What kind of attack does CVE-2022-34357 allow?
CVE-2022-34357 allows an attacker to perform Denial of Service attacks by making unlimited HTTP requests.
Is there a workaround for CVE-2022-34357 if I can't apply the fix immediately?
A temporary workaround for CVE-2022-34357 may involve implementing rate limiting at the network level until a patch can be applied.