Vulnerability Database

290,206

Total vulnerabilities in the database

CVE-2023-35011

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 257705.

  • Published: Aug 17, 2023
  • Updated: Aug 23, 2023
  • CVE: CVE-2023-35011
  • Severity: Medium
  • Exploit:

CVSS v3:

  • Severity: Medium
  • Score: 5.4
  • AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

CWEs:

Software From Fixed in
ibm / cognos_analytics 11.1.7 11.1.7.x
ibm / cognos_analytics 11.1.0 11.1.7
ibm / cognos_analytics 11.2.4-fixpack1 11.2.4-fixpack1.x
ibm / cognos_analytics 11.2.4 11.2.4.x
ibm / cognos_analytics 11.2.0 11.2.4
ibm / cognos_analytics 11.1.7-interimfix1 11.1.7-interimfix1.x
ibm / cognos_analytics 11.1.7-interimfix2 11.1.7-interimfix2.x
ibm / cognos_analytics 11.1.7-interimfix3 11.1.7-interimfix3.x
ibm / cognos_analytics 11.1.7-interimfix4 11.1.7-interimfix4.x
ibm / cognos_analytics 11.1.7-interimfix5 11.1.7-interimfix5.x
ibm / cognos_analytics 11.1.7-interimfix6 11.1.7-interimfix6.x
ibm / cognos_analytics 11.1.7-interimfix7 11.1.7-interimfix7.x
ibm / cognos_analytics 11.1.7-interimfix8 11.1.7-interimfix8.x
ibm / cognos_analytics 11.1.7-interimfix9 11.1.7-interimfix9.x