Vulnerability Database

309,136

Total vulnerabilities in the database

CVE-2022-43887

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could be vulnerable to sensitive information exposure by passing API keys to log files. If these keys contain sensitive information, it could lead to further attacks. IBM X-Force ID: 240450.

  • Published: Dec 19, 2022
  • Updated: Nov 16, 2025
  • CVE: CVE-2022-43887
  • Severity: Medium
  • Exploit:

CVSS v3:

  • Severity: Medium
  • Score: 5.3
  • AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CWEs:

Software From Fixed in
ibm / cognos_analytics 11.1.7 11.1.7.x
ibm / cognos_analytics 11.1.0 11.1.7
ibm / cognos_analytics 11.1.7-fixpack1 11.1.7-fixpack1.x
ibm / cognos_analytics 11.1.7-fixpack2 11.1.7-fixpack2.x
ibm / cognos_analytics 11.1.7-fixpack3 11.1.7-fixpack3.x
ibm / cognos_analytics 11.1.7-fixpack4 11.1.7-fixpack4.x
ibm / cognos_analytics 11.2.0 11.2.3.x
ibm / cognos_analytics 11.1.7-fixpack5 11.1.7-fixpack5.x