CVE-2023-28952: IBM Cognos Controller log injection
Published May 3, 2024
·Updated
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to injection attacks in application logging by not sanitizing user provided data. IBM X-Force ID: 251463.
Affected Software
3 affected components
IBM Cognos Controller=10.4.1
IBM Cognos Controller=10.4.2
IBM Cognos Controller=11.0.0
Event History
May 3, 2024
CVE Published
via MITRE·05:39 PM
Data Sourced
via MITRE·05:39 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-28952?
The severity of CVE-2023-28952 is considered high due to the potential for injection attacks.
2
How do I fix CVE-2023-28952?
To fix CVE-2023-28952, update IBM Cognos Controller to versions 10.4.3 or 11.0.1 where the vulnerability is addressed.
3
Which versions of IBM Cognos Controller are affected by CVE-2023-28952?
CVE-2023-28952 affects IBM Cognos Controller versions 10.4.1, 10.4.2, and 11.0.0.
4
What type of vulnerability is CVE-2023-28952?
CVE-2023-28952 is an injection vulnerability that arises from improper sanitization of user input in application logging.
5
Can CVE-2023-28952 be exploited remotely?
Yes, CVE-2023-28952 can be exploited remotely by sending crafted input to the application.