CVE-2023-50324: IBM Cognos Command Center information disclosure
IBM Cognos Command Center 10.2.4.1 and 10.2.5 exposes details the X-AspNet-Version Response Header that could allow an attacker to obtain information of the application environment to conduct further attacks. IBM X-Force ID: 275038.
Other sources
IBM Cognos Command Center exposes details the X-AspNet-Version Response Header that could allow an attacker to obtain information of the application environment to conduct further attacks.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-50324?
CVE-2023-50324 is considered a medium severity vulnerability due to its potential to expose sensitive application environment details.
How do I fix CVE-2023-50324?
To mitigate CVE-2023-50324, upgrade IBM Cognos Command Center to version 10.2.6 or later.
What information could be exposed by CVE-2023-50324?
CVE-2023-50324 may expose application environment details through the X-AspNet-Version Response Header.
What versions of IBM Cognos Command Center are affected by CVE-2023-50324?
CVE-2023-50324 affects IBM Cognos Command Center versions up to and including 10.2.5.
What type of attacks could be facilitated by CVE-2023-50324?
CVE-2023-50324 could allow attackers to gather information for conducting targeted attacks on the application.