CVE-2023-47160: IBM Cognos Controller XML external entity injection
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0
is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-47160?
CVE-2023-47160 is considered a critical vulnerability due to its potential for exposing sensitive information.
How do I fix CVE-2023-47160?
To mitigate CVE-2023-47160, upgrade to the latest version of IBM Cognos Controller or IBM Controller that addresses the XXE vulnerability.
What are the potential impacts of CVE-2023-47160?
The potential impacts of CVE-2023-47160 include unauthorized access to sensitive information and denial of service due to memory consumption.
Which versions are affected by CVE-2023-47160?
CVE-2023-47160 affects IBM Cognos Controller versions 11.0.0 through 11.0.1 FP3 and IBM Controller up to version 11.1.0.
What type of vulnerability is CVE-2023-47160?
CVE-2023-47160 is an XML External Entity Injection (XXE) vulnerability that manipulates XML data processing.