CVE-2022-34339
published 2022-11-03CVE-2022-34339: "IBM Cognos Analytics 11.2.1, 11.2.0, 11.1.7 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 229963."
PriorityP433medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.39%
31.6th percentile
"IBM Cognos Analytics 11.2.1, 11.2.0, 11.1.7 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 229963."
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | cognos_analytics | — | — |
| ibm | cognos_analytics | — | — |
| ibm | cognos_analytics | — | — |
| ibm | cognos_analytics | >= 11.1.0 < 11.1.7 | 11.1.7 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
IBM Cognos Analytics 11.1.7/11.2.0/11.2.1 cleartext storage (EUVD-2022-37294 / XFDB-229963)
vuldb·2026-06-13·CVSS 6.5
CVE-2022-34339 [MEDIUM] IBM Cognos Analytics 11.1.7/11.2.0/11.2.1 cleartext storage (EUVD-2022-37294 / XFDB-229963)
A vulnerability categorized as problematic has been discovered in IBM Cognos Analytics 11.1.7/11.2.0/11.2.1. This issue affects some unknown processing. Executing a manipulation can lead to cleartext storage of sensitive information.
This vulnerability is registered as CVE-2022-34339. The attack requires access to the local network. No exploit is available.
It is advisable to upgrade the affected component.
GHSA
GHSA-g5q2-63r8-xrq9: "IBM Cognos Analytics 11
ghsa_unreviewed·2022-11-04
CVE-2022-34339 [MEDIUM] CWE-312 GHSA-g5q2-63r8-xrq9: "IBM Cognos Analytics 11
"IBM Cognos Analytics 11.2.1, 11.2.0, 11.1.7 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 229963."
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-11-03
Published