IBM Cognos Analytics 11.0 and 11.1 DQM API allows submitting of all control requests in unauthenticated sessions. This allows a remote attacker who can access a valid CA endpoint to read and write files to the Cognos Analytics system. IBM X-Force ID: 183903.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: ibm
Published: 2021-05-31T15:10:44.659014Z
Updated: 2024-09-17T03:39:02.327Z
Reserved: 2019-12-30T00:00:00
Link: CVE-2020-4561
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-06-01T14:15:08.523
Modified: 2024-11-21T05:32:54.430
Link: CVE-2020-4561
Redhat
No data.