CVE-2023-38724: IBM Cognos Controller SQL injection
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 262183.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-38724?
CVE-2023-38724 has been classified as a critical vulnerability due to its potential to allow remote SQL injection attacks.
How do I fix CVE-2023-38724?
To fix CVE-2023-38724, upgrade IBM Cognos Controller to the latest patched version that addresses the SQL injection vulnerability.
Which versions of IBM Cognos Controller are affected by CVE-2023-38724?
CVE-2023-38724 affects IBM Cognos Controller versions 10.4.1, 10.4.2, and 11.0.0.
Can CVE-2023-38724 be exploited remotely?
Yes, CVE-2023-38724 can be exploited remotely by an attacker sending specially crafted SQL statements.
What kind of access can an attacker gain through CVE-2023-38724?
An attacker exploiting CVE-2023-38724 may gain access to view, add, modify, or delete information in the back-end database.