IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could be vulnerable to a Log Injection attack by constructing URLs from user-controlled data. This could enable malicious users to make arbitrary requests to the internal network or to the local file system. IBM X-Force ID: 240266.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
ibm cognos analytics |
||
ibm cognos analytics 11.1.7 |