CVE-2023-35011: IBM Cognos Analytics server-side request forgey
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 257705.
Other sources
IBM Cognos Analytics is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-35011?
CVE-2023-35011 is a vulnerability in IBM Cognos Analytics that allows for server-side request forgery (SSRF), potentially leading to network enumeration and other attacks.
How can an authenticated attacker exploit CVE-2023-35011?
An authenticated attacker can exploit CVE-2023-35011 by sending unauthorized requests from the system.
What is the severity of CVE-2023-35011?
The severity of CVE-2023-35011 is medium, with a severity value of 5.4.
Which versions of IBM Cognos Analytics are affected by CVE-2023-35011?
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 are affected by CVE-2023-35011.
How can I fix CVE-2023-35011?
To fix CVE-2023-35011, apply the patches provided by IBM for the affected versions of IBM Cognos Analytics.