CVE-2023-38009

MEDIUM

IBM Cognos Mobile Client 1.1 iOS - Information Disclosure via Man-in-the-Middle Attack

Title source: llm
STIX 2.1

Description

IBM Cognos Mobile Client 1.1 iOS may be vulnerable to information disclosure through man in the middle techniques due to the lack of certificate pinning.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
https://www.ibm.com/support/pages/node/7172691
Vendor Advisory vendor-advisory
https://www.ibm.com/support/pages/node/7172692

Scores

CVSS v3 4.2
EPSS 0.0006
EPSS Percentile 18.2%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-295
Status published
Products (1)
ibm/cognos_analytics 1.1
Published Jan 26, 2025
Tracked Since Feb 18, 2026