CVE-2020-4875: XEE
IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 190838.
Other sources
IBM Cognos Controller is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2020-4875.
What is the severity of CVE-2020-4875?
The severity of CVE-2020-4875 is high with a CVSS score of 8.2.
What is the affected software?
The affected software is IBM Cognos Controller versions 10.4.0, 10.4.1, and 10.4.2.
What is the impact of this vulnerability?
This vulnerability allows a remote attacker to expose sensitive information or consume memory resources.
Are there any references related to this vulnerability?
Yes, you can find more information about CVE-2020-4875 at the following links: [Link 1](https://exchange.xforce.ibmcloud.com/vulnerabilities/190838) and [Link 2](https://www.ibm.com/support/pages/node/6509856).