IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, and 10.4.1 could allow an authenticated user to obtain sensitive information due to easy to guess session identifier names. IBM X-Force ID: 162658.
| Software | From | Fixed in |
|---|---|---|
| ibm / cognos_controller | 10.3.0 | 10.3.0.x |
| ibm / cognos_controller | 10.3.1 | 10.3.1.x |
| ibm / cognos_controller | 10.4.0 | 10.4.0.x |
| ibm / cognos_controller | 10.4.1 | 10.4.1.x |