CVE-2023-28530: IBM Cognos Analytics cross-site scripting
IBM Cognos Analytics 11.1 and 11.2 is vulnerable to stored cross-site scripting, caused by improper validation of SVG Files in Custom Visualizations. A remote attacker could exploit this vulnerability to execute scripts in a victim's Web browser within the security context of the hosting Web site. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials. IBM X-Force ID: 251214.
Other sources
IBM Cognos Analytics is vulnerable to stored cross-site scripting, caused by improper validation of SVG Files in Custom Visualizations. A remote attacker could exploit this vulnerability to execute scripts in a victim's Web browser within the security context of the hosting Web site. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-28530?
The severity of CVE-2023-28530 is medium with a CVSS score of 5.4.
How does CVE-2023-28530 affect IBM Cognos Analytics?
CVE-2023-28530 affects IBM Cognos Analytics versions 11.1 and 11.2.
What is the vulnerability in IBM Cognos Analytics?
The vulnerability in IBM Cognos Analytics is stored cross-site scripting (XSS) caused by improper validation of SVG Files in Custom Visualizations.
How can a remote attacker exploit CVE-2023-28530?
A remote attacker can exploit CVE-2023-28530 to execute scripts in a victim's web browser within the security context of the hosting website.
How can I fix CVE-2023-28530 in IBM Cognos Analytics?
To fix CVE-2023-28530 in IBM Cognos Analytics, apply the relevant patches provided by IBM.