CVE-2023-35009: IBM Cognos Analytics information disclosure
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a remote attacker to obtain system information without authentication which could be used in reconnaissance to gather information that could be used for future attacks. IBM X-Force ID: 257703.
Other sources
IBM Cognos Analytics could allow a remote attacker to obtain system information without authentication which could be used in reconnaissance to gather information that could be used for future attacks.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2023-35009.
What is the severity level of CVE-2023-35009?
The severity level of CVE-2023-35009 is medium with a severity value of 5.3.
How can a remote attacker exploit CVE-2023-35009?
A remote attacker can exploit CVE-2023-35009 to obtain system information without authentication, which can be used for future attacks.
Which versions of IBM Cognos Analytics are affected by CVE-2023-35009?
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 are affected by CVE-2023-35009.
How do I fix CVE-2023-35009?
To fix CVE-2023-35009, apply the available patches provided by IBM for the affected versions of IBM Cognos Analytics.