Impact
The vulnerability arises from insecure network communication allowing an attacker on a shared network to obtain sensitive information. This weakness is classified as CWE-327, indicating improper cryptographic practices. Consequently, confidential data transmitted between the client and IBM Cognos Analytics could be intercepted or accessed by an unauthorized party.
Affected Systems
Affected deployments include IBM Cognos Analytics versions 12.1.0, 12.1.1, 12.1.2, 12.1.3, 12.1.3 FP1, 12.1.3 FP2 and 12.0.4, 12.0.4 FP2, 12.0.4 FP3. Versions outside these ranges are not impacted.
Risk and Exploitability
The CVSS base score of 5.9 reflects a moderate severity, but the EPSS score of < 1% and lack of listing in the KEV catalog suggest limited public exploitation at present. The attack vector is primarily network-based; the vulnerability can be triggered by a local actor on the same shared network segment. Although not a remote code execution flaw, an attacker can gain access to sensitive information, posing a moderate confidentiality risk.
OpenCVE Enrichment