CVE-2021-20464XML Entity Expansion in IBM Cognos Analytics

Severity
6.5MEDIUMNVD
EPSS
0.3%
top 44.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 22
Latest updateApr 23

Description

IBM Cognos Analytics PowerPlay (IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7) could be vulnerable to an XML Bomb attack by a malicious authenticated user. IBM X-Force ID: 196813.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5ibm/cognos_analytics11.1.7, 11.2.0, 11.2.1+2
NVDibm/cognos_analytics11.1.7, 11.2.0, 11.2.1+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-6cvg-3r48-6prg: IBM Cognos Analytics PowerPlay (IBM Cognos Analytics 112022-04-23
CVEList
CVE-2021-20464: IBM Cognos Analytics PowerPlay (IBM Cognos Analytics 112022-04-22
CVE-2021-20464 — XML Entity Expansion in IBM | cvebase