CVE-2023-38276: IBM Cognos Dashboards information disclosure
IBM Cognos Dashboards exposes sensitive information in environment variables which could aid in further attacks against the system.
Other sources
IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 exposes sensitive information in environment variables which could aid in further attacks against the system. IBM X-Force ID: 260736.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-38276.
What is the title of the vulnerability?
The title of the vulnerability is IBM Cognos Dashboards information disclosure.
What is the severity level of CVE-2023-38276?
The severity level of CVE-2023-38276 is medium with a severity value of 5.9.
Which version of IBM Cognos Dashboards on Cloud Pak for Data is affected by this vulnerability?
IBM Cognos Dashboards on Cloud Pak for Data version 4.7.0 is affected by this vulnerability.
How can this vulnerability be exploited?
This vulnerability can be exploited by accessing sensitive information in environment variables, which could aid in further attacks against the system.