CVE-2022-43883

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/12/2022
Last modified:
07/11/2023

Description

<br /> IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could be vulnerable to a Log Injection attack by constructing URLs from user-controlled data. This could enable attackers to make arbitrary requests to the internal network or to the local file system. IBM X-Force ID: 240266.<br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ibm:cognos_analytics:*:*:*:*:*:*:*:* 11.1.0 (including) 11.1.7 (including)
cpe:2.3:a:ibm:cognos_analytics:*:*:*:*:*:*:*:* 11.2.0 (including) 11.2.3 (including)
cpe:2.3:a:ibm:cognos_analytics:11.1.7:fixpack1:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:11.1.7:fixpack2:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:11.1.7:fixpack3:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:11.1.7:fixpack4:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:11.1.7:fixpack5:*:*:*:*:*:*