CVE-2023-32344: IBM Cognos Analytics cross-site request forgery
IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 is vulnerable to form action hijacking where it is possible to modify the form action to reference an arbitrary path. IBM X-Force ID: 255898.
Other sources
IBM Cognos Analytics is vulnerable to form action hijacking where it is possible to modify the form action to reference an arbitrary path.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-32344?
CVE-2023-32344 has been classified as a medium severity vulnerability due to its potential to allow form action hijacking.
How do I fix CVE-2023-32344?
To remediate CVE-2023-32344, users should apply the appropriate patches available for the affected versions of IBM Cognos Analytics.
What versions of IBM Cognos Analytics are affected by CVE-2023-32344?
CVE-2023-32344 affects IBM Cognos Analytics versions 11.1.7, 11.2.4, and 12.0.0.
What is form action hijacking in the context of CVE-2023-32344?
Form action hijacking in CVE-2023-32344 refers to the vulnerability that allows an attacker to modify the form action to point to an arbitrary path.
Is CVE-2023-32344 part of a larger set of vulnerabilities?
Yes, CVE-2023-32344 is identified by IBM X-Force ID: 255898, indicating it is part of IBM's continuous vulnerability management efforts.