IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could be vulnerable to sensitive information exposure by passing API keys to log files. If these keys contain sensitive information, it could lead to further attacks. IBM X-Force ID: 240450.
References
Link | Resource |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/240450 | VDB Entry Vendor Advisory |
https://www.ibm.com/support/pages/node/6841801 | Patch Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/240450 | VDB Entry Vendor Advisory |
https://www.ibm.com/support/pages/node/6841801 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 07:27
Type | Values Removed | Values Added |
---|---|---|
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/240450 - VDB Entry, Vendor Advisory | |
References | () https://www.ibm.com/support/pages/node/6841801 - Patch, Vendor Advisory |
07 Nov 2023, 03:54
Type | Values Removed | Values Added |
---|---|---|
Summary | IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could be vulnerable to sensitive information exposure by passing API keys to log files. If these keys contain sensitive information, it could lead to further attacks. IBM X-Force ID: 240450. |
Information
Published : 2022-12-19 21:15
Updated : 2024-11-21 07:27
NVD link : CVE-2022-43887
Mitre link : CVE-2022-43887
CVE.ORG link : CVE-2022-43887
JSON object : View
Products Affected
ibm
- cognos_analytics
CWE
CWE-532
Insertion of Sensitive Information into Log File