CVE-2023-23474: IBM Cognos Controller information disclosure
Published May 3, 2024
·Updated
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser. IBM X-Force ID: 245403.
Affected Software
3 affected components
IBM Cognos Controller=10.4.1
IBM Cognos Controller=10.4.2
IBM Cognos Controller=11.0.0
Event History
May 3, 2024
CVE Published
via MITRE·05:15 PM
Data Sourced
via MITRE·05:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-23474?
CVE-2023-23474 is considered a medium-severity vulnerability due to potential information disclosure.
2
How do I fix CVE-2023-23474?
To fix CVE-2023-23474, upgrade IBM Cognos Controller to a version that is not affected, as indicated by the vendor's advisory.
3
What versions of IBM Cognos Controller are affected by CVE-2023-23474?
CVE-2023-23474 affects IBM Cognos Controller versions 10.4.1, 10.4.2, and 11.0.0.
4
Can CVE-2023-23474 be exploited remotely?
Yes, CVE-2023-23474 can be exploited remotely by an attacker to obtain sensitive information.
5
What kind of information can be leaked due to CVE-2023-23474?
CVE-2023-23474 can leak sensitive information through stack traces returned by the application.