IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could be vulnerable to sensitive information exposure by passing API keys to log files. If these keys contain sensitive information, it could lead to further attacks. IBM X-Force ID: 240450.
References
Link | Resource |
---|---|
https://www.ibm.com/support/pages/node/6841801 | Patch Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/240450 | VDB Entry Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2022-12-19 13:15
Updated : 2022-12-23 11:48
NVD link : CVE-2022-43887
Mitre link : CVE-2022-43887
JSON object : View
CWE
CWE-532
Insertion of Sensitive Information into Log File
Products Affected
ibm
- cognos_analytics