← back
CVE-2021-29824

CVE-2021-29824

CVSS 3.1 LOWEPSS 0.8%
Vexday Risk Score
8Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 3.1EPSS 0.8%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
22 Apr 2022Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to priviledge escalation where a lower level user could have read access to to the 'Data Connections' page to which they don't have access. IBM X-Force ID: 204468.
CVSS:3.0/PR:L/AV:N/I:N/A:N/UI:N/C:L/S:U/AC:H/RL:O/RC:C/E:U
Affected products
IBM · Cognos Analytics