CVE-2023-30996

MEDIUM

IBM Cognos Analytics <12.0.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 could be vulnerable to information leakage due to unverified sources in messages sent between Windows objects of different origins. IBM X-Force ID: 254290.

Scores

CVSS v3 5.3
EPSS 0.0007
EPSS Percentile 22.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-346
Status published
Products (6)
ibm/cognos_analytics 11.1.7 (8 CPE variants)
ibm/cognos_analytics 11.2.4 (3 CPE variants)
ibm/cognos_analytics 12.0.0
ibm/cognos_analytics 12.0.1
ibm/cognos_analytics 11.1.1 - 11.1.7
netapp/oncommand_insight
Published Feb 26, 2024
Tracked Since Feb 18, 2026