Vulnerability Database

290,206

Total vulnerabilities in the database

CVE-2022-43887

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could be vulnerable to sensitive information exposure by passing API keys to log files. If these keys contain sensitive information, it could lead to further attacks. IBM X-Force ID: 240450.

  • Published: Dec 19, 2022
  • Updated: Nov 8, 2023
  • CVE: CVE-2022-43887
  • Severity: Medium
  • Exploit:

CVSS v3:

  • Severity: Medium
  • Score: 5.3
  • AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CWEs:

Software From Fixed in
ibm / cognos_analytics 11.1.7 11.1.7.x
ibm / cognos_analytics 11.1.0 11.1.7
ibm / cognos_analytics 11.1.7-fixpack1 11.1.7-fixpack1.x
ibm / cognos_analytics 11.1.7-fixpack2 11.1.7-fixpack2.x
ibm / cognos_analytics 11.1.7-fixpack3 11.1.7-fixpack3.x
ibm / cognos_analytics 11.1.7-fixpack4 11.1.7-fixpack4.x
ibm / cognos_analytics 11.2.0 11.2.3.x
ibm / cognos_analytics 11.1.7-fixpack5 11.1.7-fixpack5.x