CVE-2021-38904: Medium severity IBM Cognos Analytics vulnerability
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 could allow a remote attacker to obtain credentials from a user's browser via incorrect autocomplete settings. IBM X-Force ID: 209693.
Other sources
IBM Cognos Analytics could allow a remote attacker to obtain credentials from a user's browser via incorrect autocomplete settings.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-38904.
What is the title of this vulnerability?
The title of this vulnerability is 'IBM Cognos Analytics could allow a remote attacker to obtain credentials from a user's browser via incorrect autocomplete settings.'
What is the severity level of CVE-2021-38904?
CVE-2021-38904 has a severity level of medium.
Which versions of IBM Cognos Analytics are affected by CVE-2021-38904?
IBM Cognos Analytics versions 11.1.7, 11.2.0, and 11.1.7 are affected by CVE-2021-38904.
How can a remote attacker obtain credentials from a user's browser?
A remote attacker can obtain credentials from a user's browser by exploiting incorrect autocomplete settings in IBM Cognos Analytics.