First published: Wed Mar 26 2025(Updated: )
IBM Cognos Controller 11.0.0 through 11.1.0 is vulnerable to a Client-Side Desync (CSD) attack where an attacker could exploit a desynchronized browser connection that could lead to further cross-site scripting (XSS) attacks.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Controller | <=11.1.0 | |
IBM Cognos Controller | <=11.0.0 - 11.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-39163 has a medium severity rating due to its potential for exploitation through client-side attacks.
To mitigate CVE-2022-39163, upgrade IBM Cognos Controller to version 11.1.1 or later.
CVE-2022-39163 can lead to cross-site scripting (XSS) attacks due to the vulnerability in client-side desynchronization.
The affected versions include IBM Cognos Controller 11.0.0 through 11.1.0.
Yes, CVE-2022-39163 is classified as a client-side vulnerability due to the exploitation method involving browser connections.