IBM Cognos Analytics 11.2.0 through 11.2.4 FP4 and 12.0.0 through 12.0.4 is vulnerable to an Expression Language (EL) Injection vulnerability. A remote attacker could exploit this vulnerability to expose sensitive information, consume memory resources, and/or cause the server to crash when using a specially crafted EL statement.
The vulnerability (CWE-917) consists of the ability to inject a crafted EL expression, which is then interpreted and executed by the application engine on the server side. An attacker sends a specially constructed request containing a malicious EL expression, bypassing data input validation mechanisms. Execution of such an expression can lead to reading confidential data, excessive memory consumption, or causing the server to enter a denial of service state (crash).
An attacker can gain access to sensitive information processed by the server, exhaust operational memory resources, or cause IBM Cognos Analytics server to crash, resulting in service unavailability.
Apply patches available from the vendor according to references published by IBM at: https://www.ibm.com/support/pages/node/7179496
IBM Cognos Analytics versions 11.2.0 to 11.2.4 FP4 and 12.0.0 to 12.0.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:HIBM Cognos Analytics
APPIbm11.2.412.0.411.2.0 – 11.2.4 (excl.)12.0.0 – 12.0.4 (excl.)
Related vulnerabilities
IBM Cognos Analytics — nieograniczony upload plików (CWE-434)
IBM Cognos Analytics – nieuwierzytelniony dostęp do DQM API (odczyt/zapis plików)
IBM Cognos Analytics — atak XXE umożliwiający wyciek danych
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 could ...
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 is vul...