CVE-2023-32344

MEDIUM

Netapp Oncommand Insight < 11.1.7 - CSRF

Title source: rule
STIX 2.1

Description

IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 is vulnerable to form action hijacking where it is possible to modify the form action to reference an arbitrary path. IBM X-Force ID: 255898.

References (4)

Core 4

Scores

CVSS v3 4.3
EPSS 0.0003
EPSS Percentile 9.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-352
Status published
Products (6)
ibm/cognos_analytics 11.1.7 (8 CPE variants)
ibm/cognos_analytics 11.2.4 (3 CPE variants)
ibm/cognos_analytics 12.0.0
ibm/cognos_analytics 12.0.1
ibm/cognos_analytics 11.1.1 - 11.1.7
netapp/oncommand_insight
Published Feb 26, 2024
Tracked Since Feb 18, 2026