Information disclosure in OpenSearch - CVE-2023-23613
Published: December 12, 2024
Vulnerability details
The vulnerability allows a remote user to gain access to potentially sensitive information.
The vulnerability exists due to insertion of sensitive information into metadata. A remote user can send a specially-crafted request to exploit this vulnerability to obtain sensitive information, and use this information to launch further attacks against the affected system.
Affected software
Cognos Dashboards on Cloud Pak for Data
How to mitigate CVE-2023-23613
Cognos Dashboards on Cloud Pak for Data - update to 5.1