CVE-2022-39160: IBM Cognos Analytics cross-site scripting
IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 235064.
Other sources
IBM Cognos Analytics is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability CVE-2022-39160?
The vulnerability CVE-2022-39160 refers to a cross-site scripting vulnerability in IBM Cognos Analytics.
How does the vulnerability CVE-2022-39160 affect IBM Cognos Analytics?
The vulnerability CVE-2022-39160 allows users to embed arbitrary JavaScript code in the Web UI of IBM Cognos Analytics, potentially leading to credentials disclosure within a trusted session.
What is the severity of the vulnerability CVE-2022-39160?
The severity of the vulnerability CVE-2022-39160 is medium with a CVSS score of 6.1.
Which versions of IBM Cognos Analytics are affected by the vulnerability CVE-2022-39160?
IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 are affected by the vulnerability CVE-2022-39160.
How can I fix the vulnerability CVE-2022-39160 in IBM Cognos Analytics?
To fix the vulnerability CVE-2022-39160 in IBM Cognos Analytics, apply the patch provided by IBM. For more details, refer to the IBM support page.