CVE-2022-36773: XEE
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 233571.
Other sources
Maven OkHttp package could allow a remote attacker to obtain sensitive information, caused by the inclusion of sensitive information in an error message. By sending a specially-crafted request using an illegal character in a header value, an attacker could exploit this vulnerability to trigger an IllegalArgumentException whose message includes the full header value.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2022-36773?
The severity of CVE-2022-36773 is high with a CVSS score of 8.2.
How does CVE-2022-36773 impact IBM Cognos Analytics?
CVE-2022-36773 allows a remote attacker to obtain sensitive information in IBM Cognos Analytics.
How can an attacker exploit CVE-2022-36773?
An attacker can exploit CVE-2022-36773 by sending a specially-crafted request with an illegal character in a header value.
What is the affected version of IBM Cognos Analytics for CVE-2022-36773?
IBM Cognos Analytics 11.1.x and 11.2.x are affected by CVE-2022-36773.
Are there any fixes or patches available for CVE-2022-36773?
Yes, IBM has released fixes and patches for CVE-2022-36773. Please refer to the vendor's website for more information.