// For flags

CVE-2022-38708

IBM Cognos Analytics server-side request forgery

Severity Score

9.1
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

IBM Cognos Analytics 11.1.7 11.2.0, and 11.2.1 could be vulnerable to a Server-Side Request Forgery Attack (SSRF) attack by constructing URLs from user-controlled data. This could enable attackers to make arbitrary requests to the internal network or to the local file system. IBM X-Force ID: 234180.

IBM Cognos Analytics 11.1.7 11.2.0 y 11.2.1 podrían ser vulnerables a un ataque de Server-Side Request Forgery (SSRF) al construir URL a partir de datos controlados por el usuario. Esto podría permitir a los atacantes realizar solicitudes arbitrarias a la red interna o al sistema de archivos local. ID de IBM X-Force: 234180.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-08-23 CVE Reserved
  • 2022-12-19 CVE Published
  • 2024-07-11 EPSS Updated
  • 2024-08-03 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-918: Server-Side Request Forgery (SSRF)
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Ibm
Search vendor "Ibm"
Cognos Analytics
Search vendor "Ibm" for product "Cognos Analytics"
>= 11.1.0 <= 11.1.7
Search vendor "Ibm" for product "Cognos Analytics" and version " >= 11.1.0 <= 11.1.7"
-
Affected
Ibm
Search vendor "Ibm"
Cognos Analytics
Search vendor "Ibm" for product "Cognos Analytics"
>= 11.2.0 <= 11.2.3
Search vendor "Ibm" for product "Cognos Analytics" and version " >= 11.2.0 <= 11.2.3"
-
Affected
Ibm
Search vendor "Ibm"
Cognos Analytics
Search vendor "Ibm" for product "Cognos Analytics"
11.1.7
Search vendor "Ibm" for product "Cognos Analytics" and version "11.1.7"
fixpack1
Affected
Ibm
Search vendor "Ibm"
Cognos Analytics
Search vendor "Ibm" for product "Cognos Analytics"
11.1.7
Search vendor "Ibm" for product "Cognos Analytics" and version "11.1.7"
fixpack2
Affected
Ibm
Search vendor "Ibm"
Cognos Analytics
Search vendor "Ibm" for product "Cognos Analytics"
11.1.7
Search vendor "Ibm" for product "Cognos Analytics" and version "11.1.7"
fixpack3
Affected
Ibm
Search vendor "Ibm"
Cognos Analytics
Search vendor "Ibm" for product "Cognos Analytics"
11.1.7
Search vendor "Ibm" for product "Cognos Analytics" and version "11.1.7"
fixpack4
Affected
Ibm
Search vendor "Ibm"
Cognos Analytics
Search vendor "Ibm" for product "Cognos Analytics"
11.1.7
Search vendor "Ibm" for product "Cognos Analytics" and version "11.1.7"
fixpack5
Affected