Impact
The vulnerability arises because IBM Cognos Analytics stores sensitive data directly in its source code files. An authenticated user can read these files and obtain confidential information, which could then be used to facilitate further attacks such as privilege escalation or data exfiltration. This flaw is a direct information disclosure weakness.
Affected Systems
The affected products are IBM Cognos Analytics. Versions 12.1.0 through 12.1.3, including the first patch release for 12.1.3, as well as 12.0.4 up to its second patch, are impacted. The specific affected releases listed by the vendor include 12.1.0, 12.1.1, 12.1.2, 12.1.3, 12.1.3 FP1, 12.1.3 FP2, 12.0.4, and 12.0.4 FP2.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. The EPSS score is 0.00295, which is less than 1% and implies a very low but nonzero probability that this vulnerability will be exploited in the wild. No known active exploitation is listed in CISA KEV. The likely attack vector involves an authenticated user accessing the application's source code directory, as inferred from the description. Once the user has access, the exposed data could enable subsequent attacks. Applying the vendor’s patch mitigates the issue.
OpenCVE Enrichment