CVE-2021-29679Code Injection in IBM Cognos Analytics

CWE-94Code Injection3 documents3 sources
Severity
8.8HIGHNVD
EPSS
0.7%
top 27.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 15
Latest updateMay 24

Description

IBM Cognos Analytics 11.1.7 and 11.2.0 could allow an authenticated user to execute code remotely due to incorrectly neutralizaing user-contrlled input that could be interpreted a a server-side include (SSI) directive. IBM X-Force ID: 199915.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5ibm/cognos_analytics11.1.7, 11.2.0+1
NVDibm/cognos_analytics11.1.7, 11.2.0+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-7299-r4w8-x368: IBM Cognos Analytics 112022-05-24
CVEList
CVE-2021-29679: IBM Cognos Analytics 112021-10-15
CVE-2021-29679 — Code Injection in IBM Cognos Analytics | cvebase