IBM-XFORCE-234179: Medium severity ibm cognos command center vulnerability
Published May 4, 2023
·Updated
IBM Cognos Command Center information disclosure
Other sources
IBM Cognos Command Center 10.2.4.1 could allow a local attacker to obtain sensitive information due to insufficient session expiration. IBM X-Force ID: 234179.
Affected Software
2 affected components
IBM Cognos Command Center<=10.2.4.1
IBM Cognos Command Center
Event History
May 4, 2023
Advisory Published
12:00 AM
Frequently Asked Questions
1
What is the severity of IBM-XFORCE-234179?
IBM-XFORCE-234179 is considered to pose a potential risk due to information disclosure vulnerabilities.
2
How do I fix IBM-XFORCE-234179?
To mitigate IBM-XFORCE-234179, ensure that session expiration policies are properly configured and applied.
3
Who is affected by IBM-XFORCE-234179?
IBM-XFORCE-234179 affects users of IBM Cognos Command Center version 10.2.4.1 and earlier.
4
What information can be disclosed through IBM-XFORCE-234179?
IBM-XFORCE-234179 can allow a local attacker to access sensitive information by exploiting insufficient session expiration.
5
Is there a workaround for IBM-XFORCE-234179?
Yes, implementing strict session management practices can serve as a temporary workaround for IBM-XFORCE-234179.