Vulnerability Details CVE-2020-4561
IBM Cognos Analytics 11.0 and 11.1 DQM API allows submitting of all control requests in unauthenticated sessions. This allows a remote attacker who can access a valid CA endpoint to read and write files to the Cognos Analytics system. IBM X-Force ID: 183903.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.011
EPSS Ranking 77.3%
CVSS Severity
CVSS v3 Score 10.0
CVSS v2 Score 7.5
Products affected by CVE-2020-4561
-
cpe:2.3:a:ibm:cognos_analytics:11.0.0
-
cpe:2.3:a:ibm:cognos_analytics:11.1.0
-
cpe:2.3:a:netapp:oncommand_insight:-