Lucene search

K
cveIbmCVE-2022-34339
HistoryNov 03, 2022 - 8:15 p.m.

CVE-2022-34339

2022-11-0320:15:28
CWE-312
ibm
web.nvd.nist.gov
41
6
ibm
cognos analytics
user credentials
plain clear text
security vulnerability

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

6

Confidence

High

EPSS

0.001

Percentile

25.4%

“IBM Cognos Analytics 11.2.1, 11.2.0, 11.1.7 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 229963.”

Affected configurations

Nvd
Vulners
Node
ibmcognos_analyticsRange11.1.011.1.7
OR
ibmcognos_analyticsMatch11.1.7-
OR
ibmcognos_analyticsMatch11.1.7fixpack1
OR
ibmcognos_analyticsMatch11.1.7fixpack2
OR
ibmcognos_analyticsMatch11.1.7fixpack3
OR
ibmcognos_analyticsMatch11.1.7fixpack4
OR
ibmcognos_analyticsMatch11.2.0
OR
ibmcognos_analyticsMatch11.2.1
VendorProductVersionCPE
ibmcognos_analytics*cpe:2.3:a:ibm:cognos_analytics:*:*:*:*:*:*:*:*
ibmcognos_analytics11.1.7cpe:2.3:a:ibm:cognos_analytics:11.1.7:-:*:*:*:*:*:*
ibmcognos_analytics11.1.7cpe:2.3:a:ibm:cognos_analytics:11.1.7:fixpack1:*:*:*:*:*:*
ibmcognos_analytics11.1.7cpe:2.3:a:ibm:cognos_analytics:11.1.7:fixpack2:*:*:*:*:*:*
ibmcognos_analytics11.1.7cpe:2.3:a:ibm:cognos_analytics:11.1.7:fixpack3:*:*:*:*:*:*
ibmcognos_analytics11.1.7cpe:2.3:a:ibm:cognos_analytics:11.1.7:fixpack4:*:*:*:*:*:*
ibmcognos_analytics11.2.0cpe:2.3:a:ibm:cognos_analytics:11.2.0:*:*:*:*:*:*:*
ibmcognos_analytics11.2.1cpe:2.3:a:ibm:cognos_analytics:11.2.1:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "IBM Cognos Analytics ",
    "versions": [
      {
        "version": "\"11.2.1, 11.2.0, 11.1.7\"",
        "status": "affected"
      }
    ]
  }
]

Social References

More

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

6

Confidence

High

EPSS

0.001

Percentile

25.4%

Related for CVE-2022-34339