Security features bypass in Cognos Analytics on Cloud Pak for Data - CVE-2023-28953

 

Security features bypass in Cognos Analytics on Cloud Pak for Data - CVE-2023-28953

Published: October 12, 2023


Vulnerability identifier: #VU81953
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-28953
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to modify data on the system.

The vulnerability exists due to misconfigured security context. A remote user can gain unauthorized access to modify data on the system.


Affected software

Cognos Analytics on Cloud Pak for Data
Cognos Analytics Cartridge for IBM Cloud Pak for Data

How to mitigate CVE-2023-28953

Install updates from vendor's website.

Cognos Analytics on Cloud Pak for Data - update to 4.7
Cognos Analytics Cartridge for IBM Cloud Pak for Data - update to 4.7

External References

Related Security Bulletins