Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cpf6-q438-6grj

Опубликовано: 19 дек. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

IBM Cognos Analytics 11.1.7 11.2.0, and 11.2.1 could be vulnerable to a Server-Side Request Forgery Attack (SSRF) attack by constructing URLs from user-controlled data. This could enable attackers to make arbitrary requests to the internal network or to the local file system. IBM X-Force ID: 234180.

IBM Cognos Analytics 11.1.7 11.2.0, and 11.2.1 could be vulnerable to a Server-Side Request Forgery Attack (SSRF) attack by constructing URLs from user-controlled data. This could enable attackers to make arbitrary requests to the internal network or to the local file system. IBM X-Force ID: 234180.

EPSS

Процентиль: 29%
0.00106
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 6.5
nvd
около 3 лет назад

IBM Cognos Analytics 11.1.7 11.2.0, and 11.2.1 could be vulnerable to a Server-Side Request Forgery Attack (SSRF) attack by constructing URLs from user-controlled data. This could enable attackers to make arbitrary requests to the internal network or to the local file system. IBM X-Force ID: 234180.

EPSS

Процентиль: 29%
0.00106
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-918