CVE-2022-38708: IBM Cognos Analytics server-side request forgery
IBM Cognos Analytics 11.1.7 11.2.0, and 11.2.1 could be vulnerable to a Server-Side Request Forgery Attack (SSRF) attack by constructing URLs from user-controlled data. This could enable attackers to make arbitrary requests to the internal network or to the local file system. IBM X-Force ID: 234180.
Other sources
IBM Cognos Analytics could be vulnerable to a Server-Side Request Forgery Attack (SSRF) attack by constucting URLs from user-controlled data . This could enable attackers to make arbitrary requests to the internal network or to the local file system.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-38708.
What is the severity of CVE-2022-38708?
CVE-2022-38708 has a severity rating of 9.1 (critical).
Which software versions are affected by CVE-2022-38708?
IBM Cognos Analytics versions 11.1.0 to 11.1.7 and versions 11.2.0 to 11.2.3 are affected by CVE-2022-38708.
What is the impact of CVE-2022-38708?
CVE-2022-38708 could enable attackers to make arbitrary requests to the internal network or to the local file system.
How can I fix CVE-2022-38708?
To fix CVE-2022-38708, apply the relevant patches provided by IBM for IBM Cognos Analytics versions 11.1.x and 11.2.x.