First published: Tue Feb 18 2025(Updated: )
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Controller | >=11.0.0<=11.0.1 FP3 | |
IBM Cognos Controller | ||
<=11.0.0 - 11.0.1 FP3 | ||
<=11.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-47160 is considered a critical vulnerability due to its potential for exposing sensitive information.
To mitigate CVE-2023-47160, upgrade to the latest version of IBM Cognos Controller or IBM Controller that addresses the XXE vulnerability.
The potential impacts of CVE-2023-47160 include unauthorized access to sensitive information and denial of service due to memory consumption.
CVE-2023-47160 affects IBM Cognos Controller versions 11.0.0 through 11.0.1 FP3 and IBM Controller up to version 11.1.0.
CVE-2023-47160 is an XML External Entity Injection (XXE) vulnerability that manipulates XML data processing.