First published: Sat Feb 24 2024(Updated: )
IBM Cognos Analytics Mobile Server 11.1.7, 11.2.4, and 12.0.0 is vulnerable to Denial of Service due to due to weak or absence of rate limiting. By making unlimited http requests, it is possible for a single user to exhaust server resources over a period of time making service unavailable for other legitimate users. IBM X-Force ID: 230510.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Analytics | <=12.0.0-12.0.1 | |
IBM Cognos Analytics | <=11.2.0-11.2.4 FP2 | |
IBM Cognos Analytics | <=11.1.1-11.1.7 FP7 | |
NetApp OnCommand Insight | ||
IBM Cognos Analytics | >=11.1.1<11.1.7 | |
IBM Cognos Analytics | >=11.2.0<11.2.4 | |
IBM Cognos Analytics | =11.1.7 | |
IBM Cognos Analytics | =11.1.7-fixpack1 | |
IBM Cognos Analytics | =11.1.7-fixpack2 | |
IBM Cognos Analytics | =11.1.7-fixpack3 | |
IBM Cognos Analytics | =11.1.7-fixpack4 | |
IBM Cognos Analytics | =11.1.7-fixpack5 | |
IBM Cognos Analytics | =11.1.7-fixpack6 | |
IBM Cognos Analytics | =11.1.7-fixpack7 | |
IBM Cognos Analytics | =11.2.4 | |
IBM Cognos Analytics | =11.2.4-fixpack1 | |
IBM Cognos Analytics | =11.2.4-fixpack2 | |
IBM Cognos Analytics | =12.0.0 | |
IBM Cognos Analytics | =12.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.