CVE-2023-38735: IBM Cognos Dashboards improper authentication
IBM Cognos Dashboards could allow a remote attacker to bypass security restrictions, caused by a reverse tabnabbing flaw. An attacker could exploit this vulnerability and redirect a victim to a phishing site.
Other sources
IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 could allow a remote attacker to bypass security restrictions, caused by a reverse tabnabbing flaw. An attacker could exploit this vulnerability and redirect a victim to a phishing site. IBM X-Force ID: 262482.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-38735.
What is the severity level of CVE-2023-38735?
The severity level of CVE-2023-38735 is medium (5.7).
What is the affected software version?
The affected software version is IBM Cognos Dashboards on Cloud Pak for Data 4.7.0.
How can an attacker exploit this vulnerability?
An attacker could exploit this vulnerability by redirecting a victim to a phishing site.
Is there a fix available for this vulnerability?
Please refer to the official IBM support page for information on available fixes and patches.