CVE-2019-4231
CVE-2019-4231
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 4.3EPSS 0.7%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
20 Dec 2019Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 159356.
CVSS:3.0/AC:L/AV:N/PR:N/I:L/C:N/S:U/UI:R/A:N/E:U/RL:O/RC:C
Affected products
IBM · Cognos Analytics