CVE-2021-38905: Medium severity ibm cognos analytics vulnerability
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 could allow an authenticated user to view report pages that they should not have access to. IBM X-Force ID: 209697.
Other sources
iBM Cognos Analytics could allow an authenticated user to view report pages that they should not have access to.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-38905.
What is the severity level of CVE-2021-38905?
The severity level of CVE-2021-38905 is medium with a severity value of 4.3.
Which version of IBM Cognos Analytics is affected by this vulnerability?
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 are affected by this vulnerability.
What is the impact of this vulnerability?
This vulnerability allows an authenticated user to view report pages that they should not have access to.
Are there any references available for this vulnerability?
Yes, you can find references for this vulnerability at the following links: [1](https://exchange.xforce.ibmcloud.com/vulnerabilities/209697), [2](https://security.netapp.com/advisory/ntap-20220602-0003/), [3](https://www.ibm.com/support/pages/node/6570957).