CVE-2017-1779Insufficiently Protected Credentials in IBM Cognos Analytics

Severity
7.8HIGHNVD
EPSS
0.1%
top 71.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 29
Latest updateMay 13

Description

IBM Cognos Analytics 11.0 could store cached credentials locally that could be obtained by a local user. IBM X-Force ID: 136824.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5ibm/cognos_analytics8 versions+7
NVDibm/cognos_analytics8 versions+7

Patches

🔴Vulnerability Details

2
GHSA
GHSA-4w2g-jgpv-wc89: IBM Cognos Analytics 112022-05-13
CVEList
CVE-2017-1779: IBM Cognos Analytics 112018-01-29
CVE-2017-1779 — Insufficiently Protected Credentials | cvebase