CVE-2019-4174

LOW

IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, 10.4.0 - Unprotected Local File Exposure via Web Page Storage

Title source: llm
STIX 2.1

Description

IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 158879.

References (2)

Core 2
Core References
Patch, Vendor Advisory x_refsource_confirm
http://www.ibm.com/support/docview.wss?uid=ibm10886913
VDB Entry, Vendor Advisory vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/158879

Scores

CVSS v3 3.3
EPSS 0.0034
EPSS Percentile 25.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-269
Status published
Products (5)
ibm/cognos_controller 10.2.0
ibm/cognos_controller 10.2.1
ibm/cognos_controller 10.3.0
ibm/cognos_controller 10.3.1
ibm/cognos_controller 10.4.0
Published Jun 17, 2019
Tracked Since Feb 18, 2026