Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-28cw-qjjv-g5g8

Опубликовано: 19 дек. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could be vulnerable to a Log Injection attack by constructing URLs from user-controlled data. This could enable attackers to make arbitrary requests to the internal network or to the local file system. IBM X-Force ID: 240266.

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could be vulnerable to a Log Injection attack by constructing URLs from user-controlled data. This could enable attackers to make arbitrary requests to the internal network or to the local file system. IBM X-Force ID: 240266.

EPSS

Процентиль: 22%
0.00071
Низкий

7.5 High

CVSS3

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 6.5
nvd
почти 3 года назад

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could be vulnerable to a Log Injection attack by constructing URLs from user-controlled data. This could enable attackers to make arbitrary requests to the internal network or to the local file system. IBM X-Force ID: 240266.

EPSS

Процентиль: 22%
0.00071
Низкий

7.5 High

CVSS3

Дефекты

CWE-74