Know every vulnerabilitybefore it knows you.
DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.
- Feiten
IBM heeft kwetsbaarheden verholpen in IBM Cognos Controller (Versies 11.0.0 tot 11.0.1 FP3 en 11.1.0).
- Interpretaties
De kwetsbaarheden stellen een kwaadwillende in staat om aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade:
- Denial-of-Service (DoS)
- Cross-Site-Scripting (XSS)
- Omzeilen van een beveiligingsmaatregel
- Manipulatie van gegevens
- Verkrijgen van verhoogde rechten
- Uitvoer van willekeurige code (Gebruikersrechten)
- Toegang tot gevoelige informatie
De kwetsbaarheden bevinden zich zowel in de Cognos Controller-Applicatie zelf, als in onderliggende producten, zoals Java, Websphere Liberty, Apache Ant en diverse Open Source componenten, welke met Cognos Controller worden meegeleverd.
- Oplossingen
IBM heeft updates uitgebracht om de kwetsbaarheden te verhelpen. Zie bijgevoegde referenties voor meer informatie.
- Kans
medium
- Schade
high
- CWE-130
Improper Handling of Length Parameter Inconsistency
- CWE-399
CWE-399
- CWE-379
Creation of Temporary File in Directory with Insecure Permissions
- CWE-300
Channel Accessible by Non-Endpoint
- CWE-798
Use of Hard-coded Credentials
- CWE-284
Improper Access Control
- CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
- CWE-295
Improper Certificate Validation
- CWE-91
XML Injection (aka Blind XPath Injection)
- CWE-94
Improper Control of Generation of Code ('Code Injection')
- CWE-327
Use of a Broken or Risky Cryptographic Algorithm
- CWE-400
Uncontrolled Resource Consumption
- CWE-770
Allocation of Resources Without Limits or Throttling
- CWE-502
Deserialization of Untrusted Data
- CWE-377
Insecure Temporary File
- CWE-863
Incorrect Authorization
- CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- CWE-611
Improper Restriction of XML External Entity Reference
- CWE-787
Out-of-bounds Write
- CWE-20
Improper Input Validation
- CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.
Checkout DevGuard