CVE-2021-29756: CSRF
IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site request forgery (CSRF) in the My Inbox page which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 202167.
Other sources
IBM Cognos Analytics is vulnerable to cross-site request forgery (CSRF) in the My Inbox page which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for IBM Cognos Analytics?
The vulnerability ID for IBM Cognos Analytics is CVE-2021-29756.
What is the severity level of CVE-2021-29756?
The severity level of CVE-2021-29756 is medium (4.3).
How does the CSRF vulnerability affect IBM Cognos Analytics?
The CSRF vulnerability in IBM Cognos Analytics allows an attacker to execute malicious and unauthorized actions transmitted from a trusted user.
Is there a fix available for CVE-2021-29756 in IBM Cognos Analytics?
To address the CSRF vulnerability in IBM Cognos Analytics, apply the recommended security patches or updates provided by IBM.
Where can I find more information about CVE-2021-29756?
You can find more information about CVE-2021-29756 on the IBM X-Force Exchange website.