Main Banks Non-banking financial sector Cyber fraud

CVE-2020-4377

IBM Cognos Anaytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 179156.

    Product

  • ibm cognos_analytics 11.0.0
  • ibm cognos_analytics 11.1.0

Score

6.4

Source

http://nvd.nist.gov

Access-complexity

LOW

Access-vector

NETWORK