CVE-2023-30996: IBM Cognos Analytics cross-origin resource sharing
IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 could be vulnerable to information leakage due to unverified sources in messages sent between Windows objects of different origins. IBM X-Force ID: 254290.
Other sources
IBM Cognos Analytics could be vulnerable to information leakage due to unverified sources in messages sent between Windows objects of different origins.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-30996?
CVE-2023-30996 is classified with a risk level that indicates potential information leakage.
How do I fix CVE-2023-30996?
To address CVE-2023-30996, apply the necessary patches provided by IBM for the affected versions of Cognos Analytics.
Which versions are affected by CVE-2023-30996?
CVE-2023-30996 affects IBM Cognos Analytics versions 11.1.7 to 12.0.0 and their respective fix packs.
What are the consequences of CVE-2023-30996?
Exploitation of CVE-2023-30996 could lead to information leakage due to unverified message sources.
Can I check if my IBM Cognos Analytics is vulnerable to CVE-2023-30996?
You can verify the vulnerability by checking the version of your IBM Cognos Analytics against the affected versions listed.