Security features bypass in Cognos Analytics on Cloud Pak for Data - CVE-2023-28953
Published: October 12, 2023
Vulnerability identifier: #VU81953
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-28953
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to modify data on the system.
The vulnerability exists due to misconfigured security context. A remote user can gain unauthorized access to modify data on the system.
Affected software
Cognos Analytics on Cloud Pak for Data
Cognos Analytics Cartridge for IBM Cloud Pak for Data
Cognos Analytics Cartridge for IBM Cloud Pak for Data
How to mitigate CVE-2023-28953
Install updates from vendor's website.
Cognos Analytics on Cloud Pak for Data - update to 4.7
Cognos Analytics Cartridge for IBM Cloud Pak for Data - update to 4.7
Cognos Analytics Cartridge for IBM Cloud Pak for Data - update to 4.7