CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
Percentile
62.1%
IBM Cognos Analytics on Cloud Pak for Data 4.6.5 has addressed a heap-based buffer overflow vulnerability.
CVEID:CVE-2022-0185
**DESCRIPTION:**Linux Kernel is vulnerable to a heap-based buffer overflow, caused by an integer underflow in the legacy_parse_param function in fs/fs_context.c. By sending a specially-crafted request, a local authenticated attacker could overflow a buffer and execute arbitrary code on the system with root privileges.
CVSS Base score: 7.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/217455 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Affected Product(s) | Version(s) |
---|---|
IBM Cognos Analytics on Cloud Pak for Data | 4.0 |
IBM strongly recommends addressing the vulnerability now by upgrading
Affected Product(s) | Version | Fix |
---|---|---|
IBM Cognos Analytics on Cloud Pak for Data | 4.6.5 | Installing IBM Cognos Analytics on IBM Cloud Pak for Data |
None
Vendor | Product | Version | CPE |
---|---|---|---|
ibm | cognos_analytics | 11.2.4 | cpe:2.3:a:ibm:cognos_analytics:11.2.4:*:*:*:*:*:*:* |
ibm | cognos_analytics_cartridge_for_ibm_cloud_pak_for_data | any | cpe:2.3:a:ibm:cognos_analytics_cartridge_for_ibm_cloud_pak_for_data:any:*:*:*:*:*:*:* |
CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
Percentile
62.1%