First published: Fri Dec 16 2022(Updated: )
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could be vulnerable to sensitive information exposure by passing API keys to log files. If these keys contain sensitive information, it could lead to further attacks. IBM X-Force ID: 240450.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Analytics | <=11.2.x | |
IBM Cognos Analytics | <=11.1.x | |
IBM Cognos Analytics | >=11.1.0<11.1.7 | |
IBM Cognos Analytics | >=11.2.0<=11.2.3 | |
IBM Cognos Analytics | =11.1.7 | |
IBM Cognos Analytics | =11.1.7-fixpack1 | |
IBM Cognos Analytics | =11.1.7-fixpack2 | |
IBM Cognos Analytics | =11.1.7-fixpack3 | |
IBM Cognos Analytics | =11.1.7-fixpack4 | |
IBM Cognos Analytics | =11.1.7-fixpack5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-43887 is a vulnerability in IBM Cognos Analytics that could result in sensitive information exposure by passing API keys to log files.
IBM Cognos Analytics versions 11.1.0 to 11.1.7, and versions 11.2.0 to 11.2.3 are affected by CVE-2022-43887.
CVE-2022-43887 has a severity rating of 5.3 (medium).
To fix CVE-2022-43887, apply the appropriate patches provided by IBM for your version of IBM Cognos Analytics. You can find the patches on IBM's support pages.
You can find more information about CVE-2022-43887 on the IBM X-Force Exchange page and IBM's support pages.