← back
CVE-2023-30996

IBM Cognos Analytics cross-origin resource sharing

CVSS 5.3 MEDIUMEPSS 0.4%CWE-346
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.3EPSS 0.4%KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
24 Feb 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 could be vulnerable to information leakage due to unverified sources in messages sent between Windows objects of different origins. IBM X-Force ID: 254290.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected products
IBM · Cognos Analytics

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →