First published: Wed Feb 28 2024(Updated: )
IBM Cognos Command Center 10.2.4.1 and 10.2.5 exposes details the X-AspNet-Version Response Header that could allow an attacker to obtain information of the application environment to conduct further attacks. IBM X-Force ID: 275038.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Command Center | <=10.2.5 | |
IBM Cognos Command Center | <=10.2.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-50324 is considered a medium severity vulnerability due to its potential to expose sensitive application environment details.
To mitigate CVE-2023-50324, upgrade IBM Cognos Command Center to version 10.2.6 or later.
CVE-2023-50324 may expose application environment details through the X-AspNet-Version Response Header.
CVE-2023-50324 affects IBM Cognos Command Center versions up to and including 10.2.5.
CVE-2023-50324 could allow attackers to gather information for conducting targeted attacks on the application.